High severity7.5NVD Advisory· Published Feb 18, 2025· Updated Jun 17, 2026
CVE-2025-25475
CVE-2025-25475
Description
A NULL pointer dereference in the component /libsrc/dcrleccd.cc of DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service (DoS) via a crafted DICOM file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords3 versionspkg:rpm/opensuse/dcmtk&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/dcmtk&distro=openSUSE%20Tumbleweedpkg:rpm/suse/dcmtk&distro=SUSE%20Package%20Hub%2015%20SP6
< 3.6.9-bp156.4.6.1+ 2 more
- (no CPE)range: < 3.6.9-bp156.4.6.1
- (no CPE)range: < 3.6.9-2.1
- (no CPE)range: < 3.6.9-bp156.4.6.1
Patches
Vulnerability mechanics
References
3- git.dcmtk.orgnvdPatch
- github.com/DCMTK/dcmtk/commit/bffa3e9116abb7038b432443f16b1bd390e80245nvdPatch
- lists.debian.org/debian-lts-announce/2025/06/msg00025.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.