CVE Vulnerabilities

CVE-2025-53948

Double Free

Published: Aug 18, 2025 | Modified: Oct 17, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a manual restart and no authentication is required.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Sante_pacs_serverSantesoft*4.2.3 (excluding)

Potential Mitigations

References