CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 360

As cited

Copy frozen at (site build).

vulnerabilities

DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap

A white paper examines heap overflow vulnerabilities in DICOM (Digital Imaging and Communications in Medicine) parsing libraries and medical imaging systems. The research demonstrates how malformed DICOM files can trigger out-of-bounds writes in Orthanc servers during image uploads, highlighting risks in Picture Archiving and Communication Systems (PACS) that automatically ingest network-received files.

Why it matters: Medical imaging infrastructure faces direct exploitation risk from malformed DICOM files; assess your PACS decoder implementations and update affected libraries immediately.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary