A vulnerability classified as problematic was found in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The manipulation results in null pointer dereference.

This vulnerability was named CVE-2022-4981. The attack needs to be approached locally. In addition, an exploit is available.

Upgrading the affected component is advised.