Sanitize all strings passed to the exec options.
authorMarco Eichelberg <eichelberg@offis.de>
Mon, 8 Jun 2026 17:14:40 +0000 (19:14 +0200)
committerÉtienne Mollier <emollier@debian.org>
Mon, 8 Jun 2026 17:14:40 +0000 (19:14 +0200)
commitdc72c1c301e62b8d56b3d21058ff771de7629a6a
tree75f15deda25164edb37227be8cbe1dbf99269b09
parent1e0e4ae02cc7d6018c3be709ebe4b8e6fec7502a
Sanitize all strings passed to the exec options.

Applied-Upstream: edbb085e45788dccaf0e64d71534cfca925784b8
Last-Update: 2026-03-21
Bug: https://support.dcmtk.org/redmine/issues/1194
Bug-Debian: https://bugs.debian.org/1133001
Reviewed-By: Étienne Mollier <emollier@debian.org>
Sanitize the text fields from incoming DICOM associations and DICOM objects
(such as Study Instance UID, SOP Instance UID, Patient's Name) and the
calling SCU's network presentation address by removing special characters
that may be interpreted as shell escape characters when one of the
execution options (e.g. --exec-on-reception) is in use.

Thanks to Machine Spirits UG (haftungsbeschränkt) for the bug report,
detailed analysis and proof of concept.

This closes DCMTK issue #1194.

Gbp-Pq: Name CVE-2026-5663.patch
dcmnet/apps/storescp.cc
ofstd/libsrc/ofstd.cc