CVE-2026-5663
commit
edbb085e45788dccaf0e64d71534cfca925784b8
Author: Marco Eichelberg <eichelberg@offis.de>
Date: Sat Mar 21 18:35:14 2026 +0100
Sanitize all strings passed to the exec options.
Sanitize the text fields from incoming DICOM associations and DICOM objects
(such as Study Instance UID, SOP Instance UID, Patient's Name) and the
calling SCU's network presentation address by removing special characters
that may be interpreted as shell escape characters when one of the
execution options (e.g. --exec-on-reception) is in use.
Thanks to Machine Spirits UG (haftungsbeschränkt) for the bug report,
detailed analysis and proof of concept.
This closes DCMTK issue #1194.
Gbp-Pq: Name 0016-CVE-2026-5663.patch