Out-of-Bounds Affecting dcmtk package, versions <3.6.6-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.23% (14th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-DCMTK-13653041
  • published22 Oct 2025
  • disclosed21 Oct 2025

Introduced: 21 Oct 2025

CVE-2020-36855  (opens in a new tab)
CWE-119  (opens in a new tab)
CWE-121  (opens in a new tab)

How to fix?

Upgrade Debian:13 dcmtk to version 3.6.6-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream dcmtk package and not the dcmtk package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of the argument StorageQuota leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. Upgrading to version 3.6.6 is sufficient to fix this issue. The identifier of the patch is 0fef9f02e. It is recommended to upgrade the affected component.

CVSS Base Scores

version 3.1