CVE-2025-14607
authorDebian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>
Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)
committerÉtienne Mollier <emollier@debian.org>
Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)
commit 4c0e5c10079392c594d6a7abd95dd78ac0aa556a
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Tue Dec 2 09:06:30 2025 +0100

    Fixed bug in handling of odd-length data elements.

    When a dataset containing an illegal odd-length attribute with a text VR
    was read from file or received over a network connection, then accessing
    the value of that attribute with DcmElement::getString() may return a
    pointer to a string that was not properly null terminated. Using C string
    functions such as strlen() or strcpy() on that string then lead to a read
    beyond the end of a string, causing a segmentation fault.

    Thanks to Zou Dikai <zoudikai@outlook.com> for the bug report and POC.

    This closes DCMTK issue #1184.

Gbp-Pq: Name 0015-CVE-2025-14607.patch

dcmdata/libsrc/dcbytstr.cc

index ae4a9b636e28fc9f58d9e33f3c053bea17d469bd..adddbdb937b7383cd12892bc6f65e1de8582be69 100644 (file)
@@ -658,7 +658,11 @@ Uint8 *DcmByteString::newValueField()
 
         /* terminate string after real length */
         if (value != NULL)
+        {
             value[lengthField] = 0;
+            value[lengthField+1] = 0;
+        }
+
         /* enforce old (pre DCMTK 3.5.2) behaviour? */
         if (!dcmAcceptOddAttributeLength.get())
         {