7.5
CVSSv3

CVE-2025-25475

CVSSv4: NA | CVSSv3: 7.5 | CVSSv2: NA | VMScore: 850 | EPSS: 0.00091 | KEV: Not Included
Published: 18/02/2025 Updated: 20/02/2025

Vulnerability Summary

NULL Pointer Dereference DoS Vulnerability in DCMTK v3.6.9+ DEV

A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows malicious users to cause a Denial of Service (DoS) via a crafted DICOM file.

Vulnerability Trend

Vendor Advisories

Debian Bug report logs - #1098373 dcmtk: CVE-2025-25475 Package: src:dcmtk; Maintainer for src:dcmtk is Debian Med Packaging Team <debian-med-packaging@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 19 Feb 2025 19:09:01 UTC Severity: important Tags: bookworm, pending, secur ...