]> dgit.raspbian.org Git - dcmtk.git/commit
CVE-2026-12805
authorDebian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>
Tue, 7 Jul 2026 20:38:06 +0000 (22:38 +0200)
committerÉtienne Mollier <emollier@debian.org>
Tue, 7 Jul 2026 20:38:06 +0000 (22:38 +0200)
commit711005cfb1950614122daa0a41236fe876bf48ad
treed75b3aed54aff75979f2d087556ea20bdce4812c
parent698ea94865694dff86f2da560acb412e3c2a542f
CVE-2026-12805

commit 1d4b3815c0987840a983160bfc671fef63a3105b
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Sat May 23 17:07:58 2026 +0200

    Fixed buffer overflow in XMLNode::parseFile().

    Fixed a heap buffer overflow that could occur in the XML parser
    when reading from a named pipe.

    Thanks to Cristhian Daniel Rivas Zúñiga and Sebastian Andres Muñoz Morera
    (Insituto Tecnológico de Costa Rica) for the bug report and fix.

    This closes DCMTK issue #1208.

Gbp-Pq: Name 0019-CVE-2026-12805.patch
ofstd/libsrc/ofxml.cc