Impact
The vulnerability lies in the DcmDicomDir::moveRecordToTree function in DCMTK 3.7.0, where recursive processing of deeply chained directory records linked through the Offset of Referenced Lower-Level Directory Entity attribute can cause uncontrolled recursion. The resulting stack exhaustion leads to a process crash, delivering a denial‑of‑service condition. This flaw is a classic example of uncontrolled recursion (CWE‑674) and directly compromises application availability.
Affected Systems
The exploit targets OFFIS DCMTK 3.7.0 and any application built on that library, such as dcmgpdir and other media viewers that accept DICOMDIR files. The vulnerability exists only in this specific release; later tagged releases are not yet available, so the fix must be obtained from the commit or current master.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. With no EPSS data, the likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA KEV. Attackers can trigger the failure by supplying a specially crafted DICOMDIR file with an excessively deep record chain, which can be delivered locally or remotely if a vulnerable application processes files from untrusted sources. Successful exploitation results in stack exhaustion and a full application crash, preventing further processing of the file and potentially affecting other users or services running on the same host.
OpenCVE Enrichment