Impact
A weakness exists in OFFIS DCMTK version 3.7.0, specifically in the function DcmQueryRetrieveIndexDatabaseHandle::deleteOldestImages within the dcmqrdbi.cc source file of the dcmqrscp component. The flaw is a heap‑based buffer overflow triggered by a crafted request, and the description states that the attack may be launched remotely. An attacker who successfully exploits the overflow could cause the target process to crash or potentially execute arbitrary code in the heap memory region.
Affected Systems
The affected product is the OFFIS DCMTK suite, particularly the dcmqrscp module. The vulnerability is present in version 3.7.0 of the library; no other versions are explicitly mentioned. The relevant file is dcmqrdbi.cc located in the dcmqrdb directory.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate severity that is defensive but may lead to denial of service or escalation if further vulnerabilities are present. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation at present. The attack vector is remote, and the weakness is characterized by CWE‑119 and CWE‑122, pointing to buffer overflow vulnerabilities in heap memory. The risk remains moderate to high for exposed services that rely on dcmqrscp and have full network reach.
OpenCVE Enrichment