dcmtk: CVE-2025-25475

Related Vulnerabilities: CVE-2025-25475  

Debian Bug report logs - #1098373
dcmtk: CVE-2025-25475

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Wed, 19 Feb 2025 19:09:01 UTC

Severity: important

Tags: bookworm, pending, security, upstream

Found in versions dcmtk/3.6.7-9~deb12u2, dcmtk/3.6.7-9~deb12u1, dcmtk/3.6.9-3

Reply or subscribe to this bug.

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>:
Bug#1098373; Package src:dcmtk. (Wed, 19 Feb 2025 19:09:02 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>. (Wed, 19 Feb 2025 19:09:02 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: dcmtk: CVE-2025-25475
Date: Wed, 19 Feb 2025 20:05:22 +0100
Source: dcmtk
Version: 3.6.9-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>

Hi,

The following vulnerability was published for dcmtk.

CVE-2025-25475[0]:
| A NULL pointer dereference in the component /libsrc/dcrleccd.cc of
| DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service
| (DoS) via a crafted DICOM file.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-25475
    https://www.cve.org/CVERecord?id=CVE-2025-25475
[1] https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=bffa3e9116abb7038b432443f16b1bd390e80245

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



Information forwarded to debian-bugs-dist@lists.debian.org, Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>:
Bug#1098373; Package src:dcmtk. (Wed, 19 Feb 2025 21:09:02 GMT) (full text, mbox, link).


Acknowledgement sent to Étienne Mollier <emollier@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>. (Wed, 19 Feb 2025 21:09:02 GMT) (full text, mbox, link).


Message #10 received at 1098373@bugs.debian.org (full text, mbox, reply):

From: Étienne Mollier <emollier@debian.org>
To: Salvatore Bonaccorso <carnil@debian.org>, 1098373@bugs.debian.org
Subject: Re: [Debian-med-packaging] Bug#1098373: dcmtk: CVE-2025-25475
Date: Wed, 19 Feb 2025 22:05:39 +0100
[Message part 1 (text/plain, inline)]
Control: tags -1 + bookworm
Control: found -1 3.6.7-9~deb12u1
Control: found -1 3.6.7-9~deb12u2

Greetings,

Salvatore Bonaccorso, on 2025-02-19:
> [1] https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=bffa3e9116abb7038b432443f16b1bd390e80245

The change applies without much fuzz on dcmtk in bookworm, which
suggests that the version in stable (and stable-pu) was already
affected.

Have a nice day,  :)
-- 
  .''`.  Étienne Mollier <emollier@debian.org>
 : :' :  pgp: 8f91 b227 c7d6 f2b1 948c  8236 793c f67e 8f0d 11da
 `. `'   sent from /dev/pts/0, please excuse my verbosity
   `-    on air: Moongarden - Castle Of Sand
[signature.asc (application/pgp-signature, inline)]

Added tag(s) bookworm. Request was from Étienne Mollier <emollier@debian.org> to 1098373-submit@bugs.debian.org. (Wed, 19 Feb 2025 21:09:02 GMT) (full text, mbox, link).


Marked as found in versions dcmtk/3.6.7-9~deb12u1. Request was from Étienne Mollier <emollier@debian.org> to 1098373-submit@bugs.debian.org. (Wed, 19 Feb 2025 21:09:02 GMT) (full text, mbox, link).


Marked as found in versions dcmtk/3.6.7-9~deb12u2. Request was from Étienne Mollier <emollier@debian.org> to 1098373-submit@bugs.debian.org. (Wed, 19 Feb 2025 21:09:03 GMT) (full text, mbox, link).


Message sent on to Salvatore Bonaccorso <carnil@debian.org>:
Bug#1098373. (Wed, 19 Feb 2025 21:15:02 GMT) (full text, mbox, link).


Message #19 received at 1098373-submitter@bugs.debian.org (full text, mbox, reply):

From: Étienne Mollier <emollier@debian.org>
To: 1098373-submitter@bugs.debian.org
Subject: Bug#1098373 marked as pending in dcmtk
Date: Wed, 19 Feb 2025 21:14:55 +0000
Control: tag -1 pending

Hello,

Bug #1098373 in dcmtk reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/med-team/dcmtk/-/commit/b50ef7d1e65c53c3a7c612efb686f16d41f0e45b

------------------------------------------------------------------------
0009-CVE-2025-25475.patch: new: fix CVE-2025-25475.

Closes: #1098373
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1098373



Added tag(s) pending. Request was from Étienne Mollier <emollier@debian.org> to 1098373-submitter@bugs.debian.org. (Wed, 19 Feb 2025 21:15:02 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Feb 19 22:04:29 2025; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU General Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.