From 711005cfb1950614122daa0a41236fe876bf48ad Mon Sep 17 00:00:00 2001 From: Debian Med Packaging Team Date: Tue, 7 Jul 2026 22:38:06 +0200 Subject: [PATCH] CVE-2026-12805 MIME-Version: 1.0 Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit commit 1d4b3815c0987840a983160bfc671fef63a3105b Author: Marco Eichelberg Date: Sat May 23 17:07:58 2026 +0200 Fixed buffer overflow in XMLNode::parseFile(). Fixed a heap buffer overflow that could occur in the XML parser when reading from a named pipe. Thanks to Cristhian Daniel Rivas Zúñiga and Sebastian Andres Muñoz Morera (Insituto Tecnológico de Costa Rica) for the bug report and fix. This closes DCMTK issue #1208. Gbp-Pq: Name 0019-CVE-2026-12805.patch --- ofstd/libsrc/ofxml.cc | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/ofstd/libsrc/ofxml.cc b/ofstd/libsrc/ofxml.cc index c3904d29..944efbdc 100644 --- a/ofstd/libsrc/ofxml.cc +++ b/ofstd/libsrc/ofxml.cc @@ -1,6 +1,6 @@ /* * - * Copyright (C) 2011-2023, OFFIS e.V. + * Copyright (C) 2011-2026, OFFIS e.V. * All rights reserved. See COPYRIGHT file for details. * * This software and supporting documentation were slightly modified by @@ -1961,7 +1961,8 @@ XMLNode XMLNode::parseFile(XMLCSTR filename, XMLCSTR tag, XMLResults *pResults) if (f==NULL) { if (pResults) pResults->error=eXMLErrorFileNotFound; return emptyXMLNode; } fseek(f,0,SEEK_END); int l=OFstatic_cast(int, ftell(f)),headerSz=0; - if (!l) { if (pResults) pResults->error=eXMLErrorEmpty; fclose(f); return emptyXMLNode; } + // DCMTK: handle situation where ftell() returns -1 + if (l <= 0) { if (pResults) pResults->error=eXMLErrorEmpty; fclose(f); return emptyXMLNode; } fseek(f,0,SEEK_SET); unsigned char *buf=OFreinterpret_cast(unsigned char*, malloc(l+4)); l=OFstatic_cast(int, fread(buf,1,l,f)); -- 2.39.5