A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.
[
{
"source": "https://github.com/dcmtk/dcmtk/commit/bffa3e9116abb7038b432443f16b1bd390e80245",
"id": "CVE-2025-25475-080aebd3",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "dcmdata/libsrc/dcrleccd.cc"
},
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"312513902527789140787132207368160112329",
"158358958029820157104687039182207508187",
"144456739930771895532276089430615767180",
"32620995008868138340460389977170950465"
]
}
},
{
"source": "https://github.com/dcmtk/dcmtk/commit/bffa3e9116abb7038b432443f16b1bd390e80245",
"id": "CVE-2025-25475-90d7a2b0",
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "DcmRLECodecDecoder::decode",
"file": "dcmdata/libsrc/dcrleccd.cc"
},
"signature_type": "Function",
"digest": {
"length": 7388.0,
"function_hash": "167391237099498405725752917424488410657"
}
}
]