Product
DCMTK version 3.7.0 and earlier contains a heap over-read vulnerability in the ConcatenationLoader component that can lead to information disclosure or application crashes when processing malformed DICOM files.