CVE-2026-12805
authorDebian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>
Mon, 6 Jul 2026 20:39:03 +0000 (22:39 +0200)
committerÉtienne Mollier <emollier@debian.org>
Mon, 6 Jul 2026 20:39:03 +0000 (22:39 +0200)
commit94e5f626d93e99e57125767fa2556907e703b95b
treede721d5baac19b7a071cc3fe45b40e8eb55670a8
parentc4df3e45baf7004494d804d33bfcd6f1dfbc6132
CVE-2026-12805

commit 1d4b3815c0987840a983160bfc671fef63a3105b
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Sat May 23 17:07:58 2026 +0200

    Fixed buffer overflow in XMLNode::parseFile().

    Fixed a heap buffer overflow that could occur in the XML parser
    when reading from a named pipe.

    Thanks to Cristhian Daniel Rivas Zúñiga and Sebastian Andres Muñoz Morera
    (Insituto Tecnológico de Costa Rica) for the bug report and fix.

    This closes DCMTK issue #1208.

Gbp-Pq: Name CVE-2026-12805.patch
ofstd/libsrc/ofxml.cc