A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in the library dcmqrdb/libsrc/dcmqrdbi.cc of the component dcmqrscp. This manipulation causes null pointer dereference. The attack requires local access. Upgrading to version 3.7.0 is sufficient to resolve this issue. Patch name: ffb1a4a37d2c876e3feeb31df4930f2aed7fa030. You should upgrade the affected component.
{
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "3.6.1"
},
{
"last_affected": "3.6.1"
}
]
}
],
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-404",
"CWE-476"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14841.json"
}{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "3.6.0"
},
{
"last_affected": "3.6.0"
},
{
"introduced": "3.6.2"
},
{
"last_affected": "3.6.2"
},
{
"introduced": "3.6.3"
},
{
"last_affected": "3.6.3"
},
{
"introduced": "3.6.4"
},
{
"last_affected": "3.6.4"
},
{
"introduced": "3.6.5"
},
{
"last_affected": "3.6.5"
},
{
"introduced": "3.6.6"
},
{
"last_affected": "3.6.6"
},
{
"introduced": "3.6.7"
},
{
"last_affected": "3.6.7"
},
{
"introduced": "3.6.8"
},
{
"last_affected": "3.6.8"
},
{
"introduced": "3.6.9"
},
{
"last_affected": "3.6.9"
}
]
}