CVE-2025-14607 Details
Description
A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affected by this issue is the function DcmByteString::makeDicomByteString of the file dcmdata/libsrc/dcbytstr.cc of the component dcmdata. The manipulation results in memory corruption. The attack can be launched remotely. Upgrading to version 3.7.0 can resolve this issue. The patch is identified as 4c0e5c10079392c594d6a7abd95dd78ac0aa556a. You should upgrade the affected component.
A memory corruption vulnerability has been identified in OFFIS DCMTK versions through 3.6.9. The issue arises in the DcmByteString::makeDicomByteString function within the dcmdata/libsrc/dcbytstr.cc file. When a dataset containing an illegal odd-length attribute with a text Value Representation (VR) is processed, the function may overwrite the terminating null byte of the string with a padding character. This improper handling can lead to strings being incorrectly null-terminated. As a result, remote attackers could exploit this vulnerability by crafting specific datasets that cause the application to read beyond the intended memory boundaries, potentially leading to application crashes or other undefined behaviors.
Users are advised to upgrade OFFIS DCMTK to version 3.7.0, which addresses this vulnerability. The patch is available on the DCMTK GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 13, 2025CISA-ADP
Assessed Dec 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/DCMTK/dcmtk/commit/4c0e5c10079392c594d6a7abd95dd78ac0aa556a | [email protected] | Source CodeVendor |
| https://support.dcmtk.org/redmine/issues/1184 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://support.dcmtk.org/redmine/projects/dcmtk/activity?from=2025-12-02 | [email protected] | Issue TrackingVendor |
| https://support.dcmtk.org/redmine/versions/19 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/?ctiid.336283 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.336283 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/?submit.705036 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OFFIS DCMTK | <= 3.6.9 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 13, 2025 | New CVE Received | [email protected] |
Volerion