Sante PACS Server HTTP Content-Length Header Handling NULL Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of HTTP Content-Length header. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26770.

Project Subscriptions

Vendors Products
Santesoft Subscribe
Sante Pacs Server Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 29 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 24 Dec 2025 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Santesoft
Santesoft sante Pacs Server
Vendors & Products Santesoft
Santesoft sante Pacs Server

Tue, 23 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
Description Sante PACS Server HTTP Content-Length Header Handling NULL Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of HTTP Content-Length header. The issue results from the lack of proper validation of a pointer prior to accessing it. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26770.
Title Sante PACS Server HTTP Content-Length Header Handling NULL Pointer Dereference Denial-of-Service Vulnerability
Weaknesses CWE-476
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2025-12-29T18:04:50.177Z

Reserved: 2025-12-10T20:41:55.862Z

Link: CVE-2025-14501

cve-icon Vulnrichment

Updated: 2025-12-29T18:04:47.309Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-23T22:15:51.533

Modified: 2025-12-29T15:58:56.260

Link: CVE-2025-14501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-24T11:51:34Z

Weaknesses