Merge version 3.7.0+really3.7.0-2+rpi1 and 3.7.0+really3.7.0-5 to produce 3.7.0+reall... archive/raspbian/3.7.0+really3.7.0-5+rpi1 raspbian/3.7.0+really3.7.0-5+rpi1
authorRaspbian automatic forward porter <root@raspbian.org>
Sun, 21 Jun 2026 15:41:30 +0000 (16:41 +0100)
committerRaspbian automatic forward porter <root@raspbian.org>
Sun, 21 Jun 2026 15:41:30 +0000 (16:41 +0100)
1  2 
debian/changelog

index ca58e2e5d56352683afe8d4872be870bc23d39f3,828e133213f0f543189d1075c224d0df97380895..b40af147d5debdb233b4f2a588aaf6892049ae73
@@@ -1,9 -1,38 +1,45 @@@
- dcmtk (3.7.0+really3.7.0-2+rpi1) forky-staging; urgency=medium
++dcmtk (3.7.0+really3.7.0-5+rpi1) forky-staging; urgency=medium
 +
 +  [changes brought forward from 3.6.7-13+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Wed, 19 Jun 2024 20:44:47 +0000]
 +  * Disable stack clash protection, it causes assembler errors on raspbian.
 +
-  -- Raspbian forward porter <root@raspbian.org>  Sun, 31 May 2026 03:00:58 +0000
++ -- Raspbian forward porter <root@raspbian.org>  Sun, 21 Jun 2026 15:41:30 +0000
++
+ dcmtk (3.7.0+really3.7.0-5) unstable; urgency=high
+   * CVE-2026-10194.patch: new: fix CVE-2026-10194. (Closes: #1139181)
+   * d/control: add myself to uploaders.
+  -- Étienne Mollier <emollier@debian.org>  Mon, 08 Jun 2026 19:14:40 +0200
+ dcmtk (3.7.0+really3.7.0-4) unstable; urgency=medium
+   * Team upload.
+   * Revert "CVE-2026-10528-partial.patch: new: fix needed by orthanc."
+     The change is causing an ABI breakage that is going to require a
+     transition.  It is probably more appropriate to wait for the 3.7.1
+     release and coordinate the transition on a sane basis.  In the
+     meantime the change is undone.
+  -- Étienne Mollier <emollier@debian.org>  Thu, 04 Jun 2026 22:13:25 +0200
+ dcmtk (3.7.0+really3.7.0-3) unstable; urgency=medium
+   * Team upload.
+   [ Pino Toscano ]
+   * d/patches/hurd.patch: new, fix the build on GNU/Hurd.
+   [ Étienne Mollier ]
+   * CVE-2026-5663.patch: new: fix CVE-2026-5663.
+     This change introduces guardrails to prevent risks of shell code
+     injection. (Closes: #1133001)
+   * CVE-2026-10528-partial.patch: new: fix needed by orthanc.
+     This patch introduce the part of the mitigation against CVE-2026-10528
+     affecting orthanc that needs to be applied on the side of dcmtk.  See
+     also Debian bug #1138713.
+  -- Étienne Mollier <emollier@debian.org>  Wed, 03 Jun 2026 21:54:21 +0200
  
  dcmtk (3.7.0+really3.7.0-2) unstable; urgency=medium