CVE-2025-9732: DCMTK dcm2img diybrpxt.h memory corruption
Published Aug 31, 2025
·Updated
A vulnerability was identified in DCMTK up to 3.6.9. This affects an unknown function in the library dcmimage/include/dcmtk/dcmimage/diybrpxt.h of the component dcm2img. Such manipulation leads to memory corruption. Local access is required to approach this attack. The name of the patch is 7ad81d69b. It is best practice to apply a patch to resolve this issue.
Affected Software
2 affected components
DCMTK dcm2img<=3.6.9
OFFIS DCMTK<=3.6.9
Remediation
Patch Available
Event History
Aug 31, 2025
CVE Published
via MITRE·02:02 PM
Data Sourced
via MITRE·02:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 28, 57989
Event
via FIRST·02:04 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9732?
CVE-2025-9732 is classified as a high severity vulnerability due to its potential for memory corruption.
2
How do I fix CVE-2025-9732?
To fix CVE-2025-9732, update to the latest version of DCMTK, specifically beyond version 3.6.9.
3
What component is affected by CVE-2025-9732?
CVE-2025-9732 affects the dcm2img component of the DCMTK software library.
4
Is local access required to exploit CVE-2025-9732?
Yes, local access is required to exploit CVE-2025-9732.
5
What type of vulnerability is CVE-2025-9732?
CVE-2025-9732 is a memory corruption vulnerability.