CVE-2025-25472

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 18, 2025
Updated: Feb 20, 2025
CWE ID 120

Summary

CVE-2025-25472 is a buffer overflow vulnerability affecting DCMTK git master v3.6.9 and later. This issue can be exploited by attackers to cause a Denial of Service (DoS) by providing a specially crafted DCM file. The buffer overflow occurs due to improper handling of data in the DCMTK software, allowing malicious input to exceed the intended limit and overwrite adjacent memory. Successful exploitation of this vulnerability may result in the application crashing or becoming unresponsive, denying legitimate users access to the affected system. It is recommended that users of DCMTK upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share