logo

DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap

ID: 5492ab2f-cad5-51ce-81a0-c75abf74edbe

STIX ID: report--5492ab2f-cad5-51ce-81a0-c75abf74edbe

Feed Name: Cisco Talos

Threat Score
60/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Emmanuel Tacheau

...
...

This white paper presents a concrete case study showing that malformed DICOM files can trigger a heap overflow in the Orthanc medical imaging server during image upload, resulting in an out-of-bounds write; it highlights the risk posed by automatic ingestion of network-received DICOM files and the complexity of DICOM parsing in PACS systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.