{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/offis/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:offis:dcmtk:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-97059"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DCMTK (\u003c= 3.7.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","dcmtk","dicom","medical-imaging"],"_cs_type":"advisory","_cs_vendors":["OFFIS"],"content_html":"\u003cp\u003eDCMTK (DICOM Toolkit) through version 3.7.0 is susceptible to a heap over-read vulnerability within the ConcatenationLoader component. The issue stems from insufficient validation of pixel data frames; specifically, the component fails to verify that the length of the PixelData buffer matches the quantity declared in the NumberOfFrames attribute.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by crafting a malicious DICOM file containing a deliberately mismatched NumberOfFrames field. When an application utilizing this library parses the malformed file, it triggers an out-of-bounds read on the heap. This behavior may result in a crash of the service processing the DICOM data or, in specific memory layouts, the disclosure of sensitive data residing in adjacent memory segments. Given that DCMTK is widely used in medical imaging software and PACS (Picture Archiving and Communication Systems) infrastructures, this vulnerability poses a significant risk to the confidentiality and availability of sensitive patient imaging data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for memory content disclosure or denial-of-service via application crash. The impact is significant for organizations operating medical imaging environments, as any downstream application integrating the vulnerable DCMTK library is susceptible to attacks via maliciously crafted DICOM files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions focus on identifying and upgrading vulnerable library dependencies within the software supply chain:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all internal and third-party software deployments to identify applications that statically or dynamically link against DCMTK version 3.7.0 or earlier.\u003c/li\u003e\n\u003cli\u003ePrioritize patching for internet-facing or externally accessible image processing services that ingest DICOM files from untrusted sources.\u003c/li\u003e\n\u003cli\u003eMonitor vendor security advisories from OFFIS regarding the release of a patched version of DCMTK that implements proper buffer length validation for the ConcatenationLoader.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-24T14:47:40Z","date_published":"2026-09-24T14:47:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-dcmtk-heap-over-read/","summary":"DCMTK version 3.7.0 and earlier contains a heap over-read vulnerability in the ConcatenationLoader component that can lead to information disclosure or application crashes when processing malformed DICOM files.","title":"Heap Over-read Vulnerability in DCMTK ConcatenationLoader","url":"https://feed.craftedsignal.io/briefs/2026-09-dcmtk-heap-over-read/"}],"language":"en","title":"CraftedSignal Threat Feed - OFFIS","version":"https://jsonfeed.org/version/1.1"}