Impact
Uncontrolled recursion in the XML parser functions XMLNode::ParseXMLElement() and XMLNode::emptyTheNode() triggers excessive stack usage when parsing deeply nested XML. An attacker can supply a crafted XML document that causes the parser to exhaust the process stack, leading to a crash and denial of service. The flaw is a classic uncontrolled recursion vulnerability, classified as CWE-674. The parser is reached through the dcmencap utility when encapsulating CDA documents, or by any application that calls OFXMLParser::parseFile() or OFXMLParser::parseString() on untrusted input, allowing an external attacker to trigger the denial of service.
Affected Systems
The vulnerability affects OFFIS DCMTK version 3.7.0. All installations of this version that use the bundled XML parser, including dcmencap and any application that invokes OFXMLParser on arbitrary XML, are susceptible. The patch is included only in a specific commit and not yet in a tagged release beyond 3.7.0, so users must apply the commit or rebuild from the master branch.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium severity because the vulnerability results in a denial of service but does not provide remote code execution or privilege escalation. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits at this time. An attacker would need to supply a crafted XML document, potentially over a network channel if the application listens for incoming DICOM or CDA data; the likely attack vector is inferred to be remote. While no exploitation evidence is known, the lack of mitigation could allow a targeted denial of service against critical infrastructure.
OpenCVE Enrichment