Impact
A heap-based out-of-bounds read exists in the DcmRLECodecDecoder::decodeFrame() function of OFFIS DCMTK 3.7.0. When processing a crafted RLE Lossless DICOM file whose pixel data fragment is shorter than the 64‑byte RLE header, the function copies 64 bytes without validating the available length. This allows an attacker to read up to 63 bytes of adjacent heap memory or cause a crash. The weakness is classified as CWE‑125 and could expose sensitive information or trigger a denial of service.
Affected Systems
OFFIS DCMTK version 3.7.0 applications that decode RLE images frame by frame (for example, via DcmPixelData::getUncompressedFrame()) are affected. The command‑line tool dcmdrle, which uses the sibling decode() function that performs the length check, is not impacted. The fix is incorporated in commit 45469f3c30037e9c7159290e4bb74cd7b3b9ef1d; no tagged release after 3.7.0 includes it.
Risk and Exploitability
The CVSS score of 4.8 indicates medium severity. No EPSS score is available, and the vulnerability is not listed in the CISA KE surface is any system that accepts or processes external RLE DICOM files; local exploitation is possible when a malicious file is supplied to the decoder, and remote exploitation can occur if the application receives such files over a network interface. Applying the patch eliminates the vulnerability and reduces risk to zero.
OpenCVE Enrichment