From: Raspbian automatic forward porter Date: Sun, 21 Jun 2026 15:41:30 +0000 (+0100) Subject: Merge version 3.7.0+really3.7.0-2+rpi1 and 3.7.0+really3.7.0-5 to produce 3.7.0+reall... X-Git-Tag: archive/raspbian/3.7.0+really3.7.0-5+rpi1^0 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=189ab36b5b088e185086ac2436f3a35393200f81;p=dcmtk.git Merge version 3.7.0+really3.7.0-2+rpi1 and 3.7.0+really3.7.0-5 to produce 3.7.0+really3.7.0-5+rpi1 --- 189ab36b5b088e185086ac2436f3a35393200f81 diff --cc debian/changelog index ca58e2e5,828e1332..b40af147 --- a/debian/changelog +++ b/debian/changelog @@@ -1,9 -1,38 +1,45 @@@ - dcmtk (3.7.0+really3.7.0-2+rpi1) forky-staging; urgency=medium ++dcmtk (3.7.0+really3.7.0-5+rpi1) forky-staging; urgency=medium + + [changes brought forward from 3.6.7-13+rpi1 by Peter Michael Green at Wed, 19 Jun 2024 20:44:47 +0000] + * Disable stack clash protection, it causes assembler errors on raspbian. + - -- Raspbian forward porter Sun, 31 May 2026 03:00:58 +0000 ++ -- Raspbian forward porter Sun, 21 Jun 2026 15:41:30 +0000 ++ + dcmtk (3.7.0+really3.7.0-5) unstable; urgency=high + + * CVE-2026-10194.patch: new: fix CVE-2026-10194. (Closes: #1139181) + * d/control: add myself to uploaders. + + -- Étienne Mollier Mon, 08 Jun 2026 19:14:40 +0200 + + dcmtk (3.7.0+really3.7.0-4) unstable; urgency=medium + + * Team upload. + * Revert "CVE-2026-10528-partial.patch: new: fix needed by orthanc." + The change is causing an ABI breakage that is going to require a + transition. It is probably more appropriate to wait for the 3.7.1 + release and coordinate the transition on a sane basis. In the + meantime the change is undone. + + -- Étienne Mollier Thu, 04 Jun 2026 22:13:25 +0200 + + dcmtk (3.7.0+really3.7.0-3) unstable; urgency=medium + + * Team upload. + + [ Pino Toscano ] + * d/patches/hurd.patch: new, fix the build on GNU/Hurd. + + [ Étienne Mollier ] + * CVE-2026-5663.patch: new: fix CVE-2026-5663. + This change introduces guardrails to prevent risks of shell code + injection. (Closes: #1133001) + * CVE-2026-10528-partial.patch: new: fix needed by orthanc. + This patch introduce the part of the mitigation against CVE-2026-10528 + affecting orthanc that needs to be applied on the side of dcmtk. See + also Debian bug #1138713. + + -- Étienne Mollier Wed, 03 Jun 2026 21:54:21 +0200 dcmtk (3.7.0+really3.7.0-2) unstable; urgency=medium