The following vulnerability was published for dcmtk.
CVE-2025-2357[0]:
| A vulnerability was found in DCMTK 3.6.9. It has been declared as
| critical. This vulnerability affects unknown code of the component
| dcmjpls JPEG-LS Decoder. The manipulation leads to memory
| corruption. The attack can be initiated remotely. The exploit has
| been disclosed to the public and may be used. The name of the patch
| is 3239a7915. It is recommended to apply a patch to fix this issue.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.