CVE-2026-5663
authorDebian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>
Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)
committerÉtienne Mollier <emollier@debian.org>
Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)
commit626596b6e7f5edea69ddf561f87e5f5255fdb9e1
tree756ced8caf3f7697082411e040a86608723a1a93
parent8e655b2056fd9b4c6ea09c1b072415b0d8a52931
CVE-2026-5663

commit edbb085e45788dccaf0e64d71534cfca925784b8
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Sat Mar 21 18:35:14 2026 +0100

    Sanitize all strings passed to the exec options.

    Sanitize the text fields from incoming DICOM associations and DICOM objects
    (such as Study Instance UID, SOP Instance UID, Patient's Name) and the
    calling SCU's network presentation address by removing special characters
    that may be interpreted as shell escape characters when one of the
    execution options (e.g. --exec-on-reception) is in use.

    Thanks to Machine Spirits UG (haftungsbeschränkt) for the bug report,
    detailed analysis and proof of concept.

    This closes DCMTK issue #1194.

Gbp-Pq: Name 0016-CVE-2026-5663.patch
dcmnet/apps/storescp.cc
ofstd/libsrc/ofstd.cc