First published: Thu May 08 2025(Updated: )
Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Osirix MD |
Pixmeo recommends users to download the latest version of OsiriX MD https://www.osirix-viewer.com/osirix/osirix-md/ . For additional support regarding OsiriX MD, users should contact Pixmeo https://www.osirix-viewer.com/about/contact/ directly.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27578 has a high severity due to the potential for denial-of-service attacks resulting from memory corruption.
The use after free issue in CVE-2025-27578 occurs when a specially crafted DICOM file is processed, leading to memory corruption.
To fix CVE-2025-27578, ensure that you update Pixmeo OsiriX MD to the latest version that addresses this vulnerability.
CVE-2025-27578 can enable attackers to exploit the vulnerability to cause a denial-of-service condition.
Yes, any version of Pixmeo OsiriX MD is potentially affected by CVE-2025-27578 due to the underlying use after free vulnerability.