0015-CVE-2025-14607.patch: new: fix CVE-2025-14607.
authorÉtienne Mollier <emollier@debian.org>
Thu, 11 Jun 2026 18:40:33 +0000 (20:40 +0200)
committerÉtienne Mollier <emollier@debian.org>
Thu, 11 Jun 2026 18:40:33 +0000 (20:40 +0200)
Closes: #1122926
debian/patches/0015-CVE-2025-14607.patch [new file with mode: 0644]
debian/patches/series

diff --git a/debian/patches/0015-CVE-2025-14607.patch b/debian/patches/0015-CVE-2025-14607.patch
new file mode 100644 (file)
index 0000000..6d4c30c
--- /dev/null
@@ -0,0 +1,31 @@
+commit 4c0e5c10079392c594d6a7abd95dd78ac0aa556a
+Author: Marco Eichelberg <eichelberg@offis.de>
+Date:   Tue Dec 2 09:06:30 2025 +0100
+
+    Fixed bug in handling of odd-length data elements.
+    
+    When a dataset containing an illegal odd-length attribute with a text VR
+    was read from file or received over a network connection, then accessing
+    the value of that attribute with DcmElement::getString() may return a
+    pointer to a string that was not properly null terminated. Using C string
+    functions such as strlen() or strcpy() on that string then lead to a read
+    beyond the end of a string, causing a segmentation fault.
+    
+    Thanks to Zou Dikai <zoudikai@outlook.com> for the bug report and POC.
+    
+    This closes DCMTK issue #1184.
+
+--- dcmtk.orig/dcmdata/libsrc/dcbytstr.cc
++++ dcmtk/dcmdata/libsrc/dcbytstr.cc
+@@ -658,7 +658,11 @@
+         /* terminate string after real length */
+         if (value != NULL)
++        {
+             value[lengthField] = 0;
++            value[lengthField+1] = 0;
++        }
++
+         /* enforce old (pre DCMTK 3.5.2) behaviour? */
+         if (!dcmAcceptOddAttributeLength.get())
+         {
index 7bd220600dd123c7f74e4b9bfec086adad609b7d..c154368b83d9240b30310f6157c05659d199fd36 100644 (file)
@@ -10,3 +10,4 @@ remove_version.patch
 0012-CVE-2025-2357.patch
 0013-CVE-2025-9732.patch
 0014-CVE-2025-9732b.patch
+0015-CVE-2025-14607.patch