Impact
A heap-based buffer overflow occurs in the vtk-dicom library’s vtkDICOMItem::FindDataElementOrInsert routine when a DICOM data element exceeds the allocated buffer size. The overflow can corrupt heap memory, potentially causing application crashes, data loss, or other instability. No explicit evidence of code execution is provided in the description. This flaw is classified as CWE‑129 and is present in version 9.5.2 of vtk-dicom.
Affected Systems
The affected product is vtk‑dicom from the VTK project. The flaw appears in version 9.5.2 of the library and any build containing the unpatched vtkDICOMItem::FindDataElementOrInsert routine.
Risk and Exploitability
The vulnerability is triggered by processing a specially crafted DICOM file. An attacker who can supply such a file to a running vtk‑dicom instance can exploit the heap overflow, potentially causing memory corruption or application instability. The CVSS score of 8.1 indicates high severity, the EPSS score is below 1% and the issue is not listed in CISA KEV catalog, suggesting low current likelihood of exploitation. Based on the description, it is inferred that the attack vector is local or remote depending on how the vtk‑dicom instance receives input, and the likely path involves feeding a malicious DICOM file into the library via an application that parses DICOM data.
OpenCVE Enrichment