Report forwarded
to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>: Bug#1098373; Package src:dcmtk.
(Wed, 19 Feb 2025 19:09:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>.
(Wed, 19 Feb 2025 19:09:02 GMT) (full text, mbox, link).
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: dcmtk: CVE-2025-25475
Date: Wed, 19 Feb 2025 20:05:22 +0100
Source: dcmtk
Version: 3.6.9-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil@debian.org, Debian Security Team <team@security.debian.org>
Hi,
The following vulnerability was published for dcmtk.
CVE-2025-25475[0]:
| A NULL pointer dereference in the component /libsrc/dcrleccd.cc of
| DCMTK v3.6.9+ DEV allows attackers to cause a Denial of Service
| (DoS) via a crafted DICOM file.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-25475https://www.cve.org/CVERecord?id=CVE-2025-25475
[1] https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=bffa3e9116abb7038b432443f16b1bd390e80245
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
Information forwarded
to debian-bugs-dist@lists.debian.org, Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>: Bug#1098373; Package src:dcmtk.
(Wed, 19 Feb 2025 21:09:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Étienne Mollier <emollier@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>.
(Wed, 19 Feb 2025 21:09:02 GMT) (full text, mbox, link).
Control: tags -1 + bookworm
Control: found -1 3.6.7-9~deb12u1
Control: found -1 3.6.7-9~deb12u2
Greetings,
Salvatore Bonaccorso, on 2025-02-19:
> [1] https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=bffa3e9116abb7038b432443f16b1bd390e80245
The change applies without much fuzz on dcmtk in bookworm, which
suggests that the version in stable (and stable-pu) was already
affected.
Have a nice day, :)
--
.''`. Étienne Mollier <emollier@debian.org>
: :' : pgp: 8f91 b227 c7d6 f2b1 948c 8236 793c f67e 8f0d 11da
`. `' sent from /dev/pts/0, please excuse my verbosity
`- on air: Moongarden - Castle Of Sand
Added tag(s) bookworm.
Request was from Étienne Mollier <emollier@debian.org>
to 1098373-submit@bugs.debian.org.
(Wed, 19 Feb 2025 21:09:02 GMT) (full text, mbox, link).
Marked as found in versions dcmtk/3.6.7-9~deb12u1.
Request was from Étienne Mollier <emollier@debian.org>
to 1098373-submit@bugs.debian.org.
(Wed, 19 Feb 2025 21:09:02 GMT) (full text, mbox, link).
Marked as found in versions dcmtk/3.6.7-9~deb12u2.
Request was from Étienne Mollier <emollier@debian.org>
to 1098373-submit@bugs.debian.org.
(Wed, 19 Feb 2025 21:09:03 GMT) (full text, mbox, link).
Message sent on
to Salvatore Bonaccorso <carnil@debian.org>:
Bug#1098373.
(Wed, 19 Feb 2025 21:15:02 GMT) (full text, mbox, link).
Control: tag -1 pending
Hello,
Bug #1098373 in dcmtk reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:
https://salsa.debian.org/med-team/dcmtk/-/commit/b50ef7d1e65c53c3a7c612efb686f16d41f0e45b
------------------------------------------------------------------------
0009-CVE-2025-25475.patch: new: fix CVE-2025-25475.
Closes: #1098373
------------------------------------------------------------------------
(this message was generated automatically)
--
Greetings
https://bugs.debian.org/1098373
Added tag(s) pending.
Request was from Étienne Mollier <emollier@debian.org>
to 1098373-submitter@bugs.debian.org.
(Wed, 19 Feb 2025 21:15:02 GMT) (full text, mbox, link).
Debbugs is free software and licensed under the terms of the GNU General
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.