Impact
A global buffer overread occurs in the Huffman decoder of the bundled IJG JPEG libraries used by OFFIS DCMTK 3.7.0. The decoder fails to guard against Huffman symbols that specify a difference category above 15, allowing reads beyond the extend_test[] and extend_offset[] tables. The resulting memory leak can reveal sensitive data, corrupt pixel data, or trigger a crash. The defect remains unprotected unless DCMTK is compiled with a strict Huffman table check, which is disabled by default.
Affected Systems
Applications based on OFFIS DCMTK version 3.7.0, including the dcmdjpeg tool and any software that decompresses JPEG DICOM images with this library, are affected. Systems building DCMTK without enabling the strict Huffman table check are also vulnerable. No other DCMTK releases contain the fix as of the publication date.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate risk level. No EPSS score was reported, and the vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires an attacker to supply a malicious DICOM file containing a crafted JPEG stream with an oversized Huffman table. Therefore the attack vector is inferred to be local or network file‑processing, depending on how the affected software receives files. There is currently no evidence of active exploitation, but the moderate score and potential memory disclosure suggest that remediation should not be delayed.
OpenCVE Enrichment