CVE-2022-4981

LOW

DCMTK < 3.6.8 - Null Pointer Dereference in DcmQueryRetrieveConfig::readPeerList

Title source: llm
STIX 2.1

Description

A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit is now public and may be used. Upgrading to version 3.6.8 is sufficient to resolve this issue. The patch is identified as 957fb31e5. Upgrading the affected component is advised.

References (6)

Core 6
Core References
Exploit, Third Party Advisory
https://shimo.im/docs/e1Azd4dDQXUgOGqW/read
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.329029
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.329029
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.673134
Exploit, Issue Tracking, Vendor Advisory issue-tracking
https://support.dcmtk.org/redmine/issues/1026
Exploit, Third Party Advisory exploit
https://shimo.im/docs/e1Azd4dDQXUgOGqW/

Scores

CVSS v3 3.3
EPSS 0.0024
EPSS Percentile 15.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-404 CWE-476
Status published
Products (1)
offis/dcmtk < 3.6.8
Published Oct 21, 2025
Tracked Since Feb 18, 2026