openSUSE-SU-2023:0108-1
Dashboard / Vulnerabilities / openSUSE-SU-2023:0108-1
openSUSE-SU-2023:0108-1
Summary: Security update for dcmtk
Details: This update for dcmtk fixes the following issues: - CVE-2022-43272: Fixed memory leak via the T_ASC_Association object (boo#1206070) - Update to 3.6.7 (boo#1208639, boo#1208638, boo#1208637, CVE-2022-2121, CVE-2022-2120, CVE-2022-2119) - CVE-2022-2121: Fixed possible DoS via NULL pointer dereference - CVE-2022-2120: Fixed relative path traversal vulnerability - CVE-2022-2119: Fixed path traversal vulnerability See DOCS/CHANGES.367 for the full list of changes * Updated code definitions for DICOM 2022b * Fixed possible NULL pointer dereference
References: https://lists.opensuse.org/archives/list/[email protected]/thread/MKL5XGJX4U2PD4XAVAZG2YAU2LYKLQIH/, https://bugzilla.suse.com/1206070, https://bugzilla.suse.com/1208637, https://bugzilla.suse.com/1208638, https://bugzilla.suse.com/1208639, https://www.suse.com/security/cve/CVE-2022-2119, https://www.suse.com/security/cve/CVE-2022-2120, https://www.suse.com/security/cve/CVE-2022-2121, https://www.suse.com/security/cve/CVE-2022-43272
Affected packages
Package
Name: dcmtk
Purl: pkg:rpm/suse/dcmtk&distro=SUSE%20Package%20Hub%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
