openSUSE-SU-2023:0108-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2023:0108-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2023:0108-1
Related
Published
2023-05-14T22:01:36Z
Modified
2023-05-14T22:01:36Z
Summary
Security update for dcmtk
Details

This update for dcmtk fixes the following issues:

  • CVE-2022-43272: Fixed memory leak via the TASCAssociation object (boo#1206070)

  • Update to 3.6.7 (boo#1208639, boo#1208638, boo#1208637, CVE-2022-2121, CVE-2022-2120, CVE-2022-2119)

    • CVE-2022-2121: Fixed possible DoS via NULL pointer dereference
    • CVE-2022-2120: Fixed relative path traversal vulnerability
    • CVE-2022-2119: Fixed path traversal vulnerability

    See DOCS/CHANGES.367 for the full list of changes

    • Updated code definitions for DICOM 2022b
    • Fixed possible NULL pointer dereference
References

Affected packages

SUSE:Package Hub 15 SP4 / dcmtk

Package

Name
dcmtk
Purl
pkg:rpm/suse/dcmtk&distro=SUSE%20Package%20Hub%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.7-bp154.2.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libdcmtk17": "3.6.7-bp154.2.3.1",
            "dcmtk": "3.6.7-bp154.2.3.1",
            "dcmtk-devel": "3.6.7-bp154.2.3.1"
        }
    ]
}

openSUSE:Leap 15.4 / dcmtk

Package

Name
dcmtk
Purl
pkg:rpm/opensuse/dcmtk&distro=openSUSE%20Leap%2015.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.6.7-bp154.2.3.1

Ecosystem specific

{
    "binaries": [
        {
            "libdcmtk17": "3.6.7-bp154.2.3.1",
            "dcmtk": "3.6.7-bp154.2.3.1",
            "dcmtk-devel": "3.6.7-bp154.2.3.1"
        }
    ]
}