Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12805

Опубликовано: 21 июн. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

A flaw was found in OFFIS DCMTK. A remote attacker could exploit this vulnerability by manipulating input to the XMLNode::parseFile function. This can lead to a heap-based buffer overflow, a type of memory corruption, which may result in information disclosure or denial of service.

Отчет

This Moderate impact vulnerability in OFFIS DCMTK allows a remote attacker to trigger a heap-based buffer overflow by providing specially crafted XML input to the XMLNode::parseFile function. Successful exploitation could lead to information disclosure or denial of service. The public availability of exploit details increases the risk.

Меры по смягчению последствий

Users should avoid processing untrusted or unverified XML files with applications that rely on the OFFIS DCMTK library. Implementing strict input validation and restricting the sources of XML data can reduce the exposure to this vulnerability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2491215dcmtk: OFFIS DCMTK: Heap-based buffer overflow in XML parsing

EPSS

Процентиль: 38%
0.00468
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 2 месяцев назад

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 6.3
nvd
около 2 месяцев назад

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS3: 6.3
debian
около 2 месяцев назад

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element ...

CVSS3: 6.3
github
около 2 месяцев назад

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

EPSS

Процентиль: 38%
0.00468
Низкий

6.3 Medium

CVSS3

Уязвимость CVE-2026-12805