CVE-2026-5663
authorDebian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>
Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)
committerÉtienne Mollier <emollier@debian.org>
Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)
commita9d4b661242aa6fdd2ffbbbc7d8cec6ab9c38164
tree274c5af3f7deaa3723f239081f5800c3d17b9379
parent834259ed2a5805ebc837c4f5d46952a1c448429f
CVE-2026-5663

commit edbb085e45788dccaf0e64d71534cfca925784b8
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Sat Mar 21 18:35:14 2026 +0100

    Sanitize all strings passed to the exec options.

    Sanitize the text fields from incoming DICOM associations and DICOM objects
    (such as Study Instance UID, SOP Instance UID, Patient's Name) and the
    calling SCU's network presentation address by removing special characters
    that may be interpreted as shell escape characters when one of the
    execution options (e.g. --exec-on-reception) is in use.

    Thanks to Machine Spirits UG (haftungsbeschränkt) for the bug report,
    detailed analysis and proof of concept.

    This closes DCMTK issue #1194.

Gbp-Pq: Name 0016-CVE-2026-5663.patch
dcmnet/apps/storescp.cc
ofstd/libsrc/ofstd.cc