Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian 11 DLA-4227-1 important: dcmtk remote code execution risks

debian lts
Calendar Grey June 24, 2025
Dist Debian Esm H88
Several security flaws identified in dcmtk have been patched, which could allow for remote code execution and denial of service in Debian LTS.
Multiple vulnerabilities were fixed in dcmtk an OFFIS DICOM toolkit

Summary

CVE-2022-2119/CVE-2022-2120

Path traversal issues were found, allowing an attacker
to write DICOM files into arbitrary directories under
controlled names. This could allow remote code execution.

CVE-2024-47796

An improper array index validation vulnerability exists
in the nowindow functionality.
A specially crafted DICOM file can lead to an out-of-bounds write.

CVE-2025-2357

An issue was found in the dcmjpls JPEG-LS Decoder.
The manipulation leads to memory corruption.

CVE-2025-25472

A buffer overflow was found that cause a Denial of Service
(DoS) via a crafted DCM file.


CVE-2025-25474

A buffer overflow was found via the component
dcmimgle/diinpxt.h

CVE-2025-25475

A NULL pointer dereference was found in the component /libsrc/dcrleccd.cc

For Debian 11 bullseye, these problems have been fixed in version
3.6.5-1+deb11u4.

We recommend that you upgrade your dcmtk packages.

For the detailed security status of dcmtk please refer to
its security tracker page at:

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Package: dcmtk
Version: 3.6.5-1+deb11u4
CVE ID: CVE-2022-2119 CVE-2022-2120 CVE-2024-47796 CVE-2025-2357
Debian Bug: 1017743 1098373 1098374 1100724

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here