CVE-2026-12805: OFFIS DCMTK ofxml.cc parseFile heap-based overflow
A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. This patch is called 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OFFIS DCMTKto a version that resolves this vulnerability.Patch 1d4b3815c0987840a983160bfc671fef63a3105b
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12805?
CVE-2026-12805 has a severity rating of medium with a score of 6.3.
How does CVE-2026-12805 affect the OFFIS DCMTK software?
CVE-2026-12805 affects the XMLNode::parseFile function in OFFIS DCMTK, potentially leading to a heap-based buffer overflow.
Can CVE-2026-12805 be exploited remotely?
Yes, CVE-2026-12805 can be exploited from a remote location, allowing attackers to manipulate the software.
What impact does CVE-2026-12805 have on confidentiality, integrity, and availability?
CVE-2026-12805 could affect confidentiality and integrity due to the buffer overflow, as well as availability from potential crashes.
How can I mitigate the risk of CVE-2026-12805?
To mitigate the risk of CVE-2026-12805, it is recommended to update OFFIS DCMTK to a version that has addressed this vulnerability.