dcmtk.git
5 days agoMerge version 3.6.9-5+rpi1 and 3.6.9-5+deb13u2 to produce 3.6.9-5+rpi1+deb13u2 trixie-staging archive/raspbian/3.6.9-5+rpi1+deb13u2 raspbian/3.6.9-5+rpi1+deb13u2
Raspbian automatic forward porter [Tue, 21 Jul 2026 11:23:02 +0000 (12:23 +0100)]
Merge version 3.6.9-5+rpi1 and 3.6.9-5+deb13u2 to produce 3.6.9-5+rpi1+deb13u2

4 weeks agoMake fast forward from 3.6.9-5+deb13u1
Étienne Mollier [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
Make fast forward from 3.6.9-5+deb13u1

[dgit --quilt=gbp]

4 weeks agoCVE-2026-12805
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2026-12805

commit 1d4b3815c0987840a983160bfc671fef63a3105b
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Sat May 23 17:07:58 2026 +0200

    Fixed buffer overflow in XMLNode::parseFile().

    Fixed a heap buffer overflow that could occur in the XML parser
    when reading from a named pipe.

    Thanks to Cristhian Daniel Rivas Zúñiga and Sebastian Andres Muñoz Morera
    (Insituto Tecnológico de Costa Rica) for the bug report and fix.

    This closes DCMTK issue #1208.

Gbp-Pq: Name 0019-CVE-2026-12805.patch

4 weeks agoCVE-2026-10194
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2026-10194

commit 0f78a4ef6f645ea5530166e445e5436a5de58e75
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Mon May 4 17:48:30 2026 +0200

    Fixed remote heap buffer overflow in dcmqrscp.

    Thanks to 'elp3pinill0' for the bug report, detailed
    analysis, proof of concept and proposed fix.

    This closes DCMTK issue #1206.

Gbp-Pq: Name 0018-CVE-2026-10194.patch

4 weeks agoCVE-2025-14841
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2025-14841

commit ffb1a4a37d2c876e3feeb31df4930f2aed7fa030
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Fri Nov 28 12:24:07 2025 +0100

    Fixed two possible segfaults in dcmqrscp.

    Fixed two places where invalid messages may trigger a segmentation fault
    due to a NULL pointer being de-referenced.

    Thanks to 邹 迪凯 <zoudikai@outlook.com> for the bug report and proof-of-concept.

Gbp-Pq: Name 0017-CVE-2025-14841.patch

4 weeks agoCVE-2026-5663
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2026-5663

commit edbb085e45788dccaf0e64d71534cfca925784b8
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Sat Mar 21 18:35:14 2026 +0100

    Sanitize all strings passed to the exec options.

    Sanitize the text fields from incoming DICOM associations and DICOM objects
    (such as Study Instance UID, SOP Instance UID, Patient's Name) and the
    calling SCU's network presentation address by removing special characters
    that may be interpreted as shell escape characters when one of the
    execution options (e.g. --exec-on-reception) is in use.

    Thanks to Machine Spirits UG (haftungsbeschränkt) for the bug report,
    detailed analysis and proof of concept.

    This closes DCMTK issue #1194.

Gbp-Pq: Name 0016-CVE-2026-5663.patch

4 weeks agoCVE-2025-14607
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2025-14607

commit 4c0e5c10079392c594d6a7abd95dd78ac0aa556a
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Tue Dec 2 09:06:30 2025 +0100

    Fixed bug in handling of odd-length data elements.

    When a dataset containing an illegal odd-length attribute with a text VR
    was read from file or received over a network connection, then accessing
    the value of that attribute with DcmElement::getString() may return a
    pointer to a string that was not properly null terminated. Using C string
    functions such as strlen() or strcpy() on that string then lead to a read
    beyond the end of a string, causing a segmentation fault.

    Thanks to Zou Dikai <zoudikai@outlook.com> for the bug report and POC.

    This closes DCMTK issue #1184.

Gbp-Pq: Name 0015-CVE-2025-14607.patch

4 weeks agoCVE-2025-9732b
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2025-9732b

commit 3de96da6cd66b1af7224561c568bc3de50cd1398
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Mon Aug 18 17:58:56 2025 +0200

    Fixed issue with commit 7ad81d69b.

    Fixed an issue with recently committed changes that fix a problem with
    invalid YBR_FULL images

Gbp-Pq: Name 0014-CVE-2025-9732b.patch

4 weeks agoCVE-2025-9732
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2025-9732

commit 7ad81d69b19714936e18ea5fc74edaeb9f021ce7
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Fri Aug 15 13:35:40 2025 +0200

    Fixed issue with invalid "YBR_FULL" DICOM images.

    Fixed an issue when processing an invalid DICOM image with a Photometric
    Interpretation of "YBR_FULL" and a Planar Configuration of "1" where
    the number of pixels stored does not match the expected number of pixels
    (much too less). Now, the pixel data of such an image is not processed
    at all, but an empty image (black pixels) is created instead. The user
    is warned about this by an appropriate log message.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0013-CVE-2025-9732.patch

4 weeks agoFixed segfault in JPEG-LS decoder.
Marco Eichelberg [Mon, 3 Mar 2025 10:33:18 +0000 (11:33 +0100)]
Fixed segfault in JPEG-LS decoder.

X-Git-Url: http://git.dcmtk.org/?p=dcmtk.git;a=commitdiff_plain;h=3239a791542e1ea433d23aaa9e0a05a532ffabff;hp=92fc86e9e8d0808880bcc82e25982b2a61323cb8

Fixed segfault in JPEG-LS decoder.

Fixed a bug in the JPEG-LS decoder that led to a segmentation fault if invalid
input data was processed, due to insufficient validation of input data.

Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
and the sample file (PoC).

This closes DCMTK issue #1155.

Gbp-Pq: Name 0012-CVE-2025-2357.patch

4 weeks agoCVE-2025-25472
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2025-25472

commit 410ffe2019b9db6a8f4036daac742a6f5e4d36c2
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Fri Jan 17 17:53:50 2025 +0100

    Fixed another issue with invalid mono images.

    Fixed issue when rendering an invalid monochrome DICOM image where the
    number of pixels stored does not match the expected number of pixels.
    In this case, only a single pixel is processed, but the pixel matrix is
    much larger. Filling the rest of the pixel matrix with the smallest
    possible value for the image is not working because of an optimized
    memory usage (value would be out of range). Now, the pixel value to be
    used is double-checked before it is actually filled into the "background"
    of the image.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0011-CVE-2025-25472.patch

4 weeks agoCVE-2025-25474
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2025-25474

commit 1d205bcd307164c99e0d4bbf412110372658d847
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Tue Jan 21 11:12:28 2025 +0100

    Fixed another issue with invalid DICOM images.

    Fixed issue when processing an invalid DICOM image where the number of
    pixels stored does not match the expected number of pixels (too less)
    and the combination of BitsAllocated and BitsStored is really unusual
    (e.g. 1 bit stored, but 52 bits allocated). In cases where the last
    pixel (e.g. a single bit) does not fit into the buffer of the input
    pixel data, a buffer overflow occurred on the heap. Now, the last entry
    of the buffer is filled with the smallest possible value (e.g. 0 in case
    of unsigned data).

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0010-CVE-2025-25474.patch

4 weeks agoCVE-2025-25475
Debian Med Packaging Team [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
CVE-2025-25475

commit bffa3e9116abb7038b432443f16b1bd390e80245
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Thu Jan 23 15:51:21 2025 +0100

    Fixed issue with invalid RLE compressed DICOM images.

    Fixed issue when processing an RLE compressed image where the RLE header
    contains an invalid stripe size.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0009-CVE-2025-25475.patch

4 weeks agoAdded check to make sure: HighBit < BitsAllocated.
Joerg Riesmeier [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
Added check to make sure: HighBit < BitsAllocated.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=03e851b0586d05057c3268988e180ffb426b2e03
Bug-Debian: https://bugs.debian.org/1093047
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Added check to the image preprocessing to make sure that the value of
HighBit is always less than the value of BitsAllocated. Before, this
missing check could lead to memory corruption if an invalid combination
of values was retrieved from a malformed DICOM dataset.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the report, sample file (PoC)
and detailed analysis. See TALOS-2024-2121 and CVE-2024-52333.

Gbp-Pq: Name 0008-CVE-2024-52333.patch

4 weeks agoFixed issue rendering invalid monochrome image.
Joerg Riesmeier [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
Fixed issue rendering invalid monochrome image.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6
Bug-Debian: https://bugs.debian.org/1093043
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Fixed issue when rendering an invalid monochrome DICOM image where the
number of pixels stored does not match the expected number of pixels.
If the stored number is less than the expected number, the rest of the
pixel matrix for the intermediate representation was always filled with
the value 0. Under certain, very rare conditions, this could result in
memory problems reported by an Address Sanitizer (ASAN). Now, the rest
of the matrix is filled with the smallest possible value for the image.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the original report, the sample
file (PoC) and further details. See TALOS-2024-2122 and CVE-2024-47796.

Gbp-Pq: Name 0007-CVE-2024-47796.patch

4 weeks agoRemove version
Mathieu Malaterre [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
Remove version

Forwarded: not-needed
Bug-Debian: https://bugs.debian.org/1098944
Last-Update: 2025-03-21

Gbp-Pq: Name remove_version.patch

4 weeks agoDon't add executables to cmake exports
Gert Wollny [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
Don't add executables to cmake exports

Bug-Debian: https://bugs.debian.org/803304
Forwarded: not-needed

CMake exports are used by other packages that compile
and link against dcmtk. Because Debian moves some of
these executables and also dosn't install the test
executables, this import may fail leading to failure
to configure the according package.
===================================================================

Gbp-Pq: Name 07_dont_export_all_executables.patch

4 weeks agoThe original maintainer Jürgen Salk applied
Jürgen Salk [Tue, 23 Jun 2026 19:44:21 +0000 (21:44 +0200)]
The original maintainer Jürgen Salk applied

Forwarded: not-needed

a set of patches to the original code.  This file contains
changes to C++ code

Gbp-Pq: Name 01_dcmtk_3.6.0-1.patch

4 weeks agod/changelog: ready for trixie proposed upload.
Étienne Mollier [Tue, 23 Jun 2026 19:45:09 +0000 (21:45 +0200)]
d/changelog: ready for trixie proposed upload.

4 weeks agoCVE-2026-12805.patch: new: fix CVE-2026-12805.
Étienne Mollier [Tue, 23 Jun 2026 19:42:21 +0000 (21:42 +0200)]
CVE-2026-12805.patch: new: fix CVE-2026-12805.

This patch fixes a risk of buffer overflow by ensuring negative error
codes in XMLNode::parseFile are properly handled, as well a NULL
values.

Closes: #1140562
6 weeks agod/changelog: ready for upload to trixie.
Étienne Mollier [Thu, 11 Jun 2026 18:55:54 +0000 (20:55 +0200)]
d/changelog: ready for upload to trixie.

6 weeks agoDeclare fast forward from 3.6.9-5
Étienne Mollier [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
Declare fast forward from 3.6.9-5

[dgit --quilt=gbp --overwrite]

6 weeks agoCVE-2026-10194
Debian Med Packaging Team [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
CVE-2026-10194

commit 0f78a4ef6f645ea5530166e445e5436a5de58e75
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Mon May 4 17:48:30 2026 +0200

    Fixed remote heap buffer overflow in dcmqrscp.

    Thanks to 'elp3pinill0' for the bug report, detailed
    analysis, proof of concept and proposed fix.

    This closes DCMTK issue #1206.

Gbp-Pq: Name 0018-CVE-2026-10194.patch

6 weeks agoCVE-2025-14841
Debian Med Packaging Team [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
CVE-2025-14841

commit ffb1a4a37d2c876e3feeb31df4930f2aed7fa030
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Fri Nov 28 12:24:07 2025 +0100

    Fixed two possible segfaults in dcmqrscp.

    Fixed two places where invalid messages may trigger a segmentation fault
    due to a NULL pointer being de-referenced.

    Thanks to 邹 迪凯 <zoudikai@outlook.com> for the bug report and proof-of-concept.

Gbp-Pq: Name 0017-CVE-2025-14841.patch

6 weeks agoCVE-2026-5663
Debian Med Packaging Team [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
CVE-2026-5663

commit edbb085e45788dccaf0e64d71534cfca925784b8
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Sat Mar 21 18:35:14 2026 +0100

    Sanitize all strings passed to the exec options.

    Sanitize the text fields from incoming DICOM associations and DICOM objects
    (such as Study Instance UID, SOP Instance UID, Patient's Name) and the
    calling SCU's network presentation address by removing special characters
    that may be interpreted as shell escape characters when one of the
    execution options (e.g. --exec-on-reception) is in use.

    Thanks to Machine Spirits UG (haftungsbeschränkt) for the bug report,
    detailed analysis and proof of concept.

    This closes DCMTK issue #1194.

Gbp-Pq: Name 0016-CVE-2026-5663.patch

6 weeks agoCVE-2025-14607
Debian Med Packaging Team [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
CVE-2025-14607

commit 4c0e5c10079392c594d6a7abd95dd78ac0aa556a
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Tue Dec 2 09:06:30 2025 +0100

    Fixed bug in handling of odd-length data elements.

    When a dataset containing an illegal odd-length attribute with a text VR
    was read from file or received over a network connection, then accessing
    the value of that attribute with DcmElement::getString() may return a
    pointer to a string that was not properly null terminated. Using C string
    functions such as strlen() or strcpy() on that string then lead to a read
    beyond the end of a string, causing a segmentation fault.

    Thanks to Zou Dikai <zoudikai@outlook.com> for the bug report and POC.

    This closes DCMTK issue #1184.

Gbp-Pq: Name 0015-CVE-2025-14607.patch

6 weeks agoCVE-2025-9732b
Debian Med Packaging Team [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
CVE-2025-9732b

commit 3de96da6cd66b1af7224561c568bc3de50cd1398
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Mon Aug 18 17:58:56 2025 +0200

    Fixed issue with commit 7ad81d69b.

    Fixed an issue with recently committed changes that fix a problem with
    invalid YBR_FULL images

Gbp-Pq: Name 0014-CVE-2025-9732b.patch

6 weeks agoCVE-2025-9732
Debian Med Packaging Team [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
CVE-2025-9732

commit 7ad81d69b19714936e18ea5fc74edaeb9f021ce7
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Fri Aug 15 13:35:40 2025 +0200

    Fixed issue with invalid "YBR_FULL" DICOM images.

    Fixed an issue when processing an invalid DICOM image with a Photometric
    Interpretation of "YBR_FULL" and a Planar Configuration of "1" where
    the number of pixels stored does not match the expected number of pixels
    (much too less). Now, the pixel data of such an image is not processed
    at all, but an empty image (black pixels) is created instead. The user
    is warned about this by an appropriate log message.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0013-CVE-2025-9732.patch

6 weeks agoFixed segfault in JPEG-LS decoder.
Marco Eichelberg [Mon, 3 Mar 2025 10:33:18 +0000 (11:33 +0100)]
Fixed segfault in JPEG-LS decoder.

X-Git-Url: http://git.dcmtk.org/?p=dcmtk.git;a=commitdiff_plain;h=3239a791542e1ea433d23aaa9e0a05a532ffabff;hp=92fc86e9e8d0808880bcc82e25982b2a61323cb8

Fixed segfault in JPEG-LS decoder.

Fixed a bug in the JPEG-LS decoder that led to a segmentation fault if invalid
input data was processed, due to insufficient validation of input data.

Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
and the sample file (PoC).

This closes DCMTK issue #1155.

Gbp-Pq: Name 0012-CVE-2025-2357.patch

6 weeks agoCVE-2025-25472
Debian Med Packaging Team [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
CVE-2025-25472

commit 410ffe2019b9db6a8f4036daac742a6f5e4d36c2
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Fri Jan 17 17:53:50 2025 +0100

    Fixed another issue with invalid mono images.

    Fixed issue when rendering an invalid monochrome DICOM image where the
    number of pixels stored does not match the expected number of pixels.
    In this case, only a single pixel is processed, but the pixel matrix is
    much larger. Filling the rest of the pixel matrix with the smallest
    possible value for the image is not working because of an optimized
    memory usage (value would be out of range). Now, the pixel value to be
    used is double-checked before it is actually filled into the "background"
    of the image.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0011-CVE-2025-25472.patch

6 weeks agoCVE-2025-25474
Debian Med Packaging Team [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
CVE-2025-25474

commit 1d205bcd307164c99e0d4bbf412110372658d847
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Tue Jan 21 11:12:28 2025 +0100

    Fixed another issue with invalid DICOM images.

    Fixed issue when processing an invalid DICOM image where the number of
    pixels stored does not match the expected number of pixels (too less)
    and the combination of BitsAllocated and BitsStored is really unusual
    (e.g. 1 bit stored, but 52 bits allocated). In cases where the last
    pixel (e.g. a single bit) does not fit into the buffer of the input
    pixel data, a buffer overflow occurred on the heap. Now, the last entry
    of the buffer is filled with the smallest possible value (e.g. 0 in case
    of unsigned data).

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0010-CVE-2025-25474.patch

6 weeks agoCVE-2025-25475
Debian Med Packaging Team [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
CVE-2025-25475

commit bffa3e9116abb7038b432443f16b1bd390e80245
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Thu Jan 23 15:51:21 2025 +0100

    Fixed issue with invalid RLE compressed DICOM images.

    Fixed issue when processing an RLE compressed image where the RLE header
    contains an invalid stripe size.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0009-CVE-2025-25475.patch

6 weeks agoAdded check to make sure: HighBit < BitsAllocated.
Joerg Riesmeier [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
Added check to make sure: HighBit < BitsAllocated.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=03e851b0586d05057c3268988e180ffb426b2e03
Bug-Debian: https://bugs.debian.org/1093047
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Added check to the image preprocessing to make sure that the value of
HighBit is always less than the value of BitsAllocated. Before, this
missing check could lead to memory corruption if an invalid combination
of values was retrieved from a malformed DICOM dataset.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the report, sample file (PoC)
and detailed analysis. See TALOS-2024-2121 and CVE-2024-52333.

Gbp-Pq: Name 0008-CVE-2024-52333.patch

6 weeks agoFixed issue rendering invalid monochrome image.
Joerg Riesmeier [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
Fixed issue rendering invalid monochrome image.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6
Bug-Debian: https://bugs.debian.org/1093043
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Fixed issue when rendering an invalid monochrome DICOM image where the
number of pixels stored does not match the expected number of pixels.
If the stored number is less than the expected number, the rest of the
pixel matrix for the intermediate representation was always filled with
the value 0. Under certain, very rare conditions, this could result in
memory problems reported by an Address Sanitizer (ASAN). Now, the rest
of the matrix is filled with the smallest possible value for the image.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the original report, the sample
file (PoC) and further details. See TALOS-2024-2122 and CVE-2024-47796.

Gbp-Pq: Name 0007-CVE-2024-47796.patch

6 weeks agoRemove version
Mathieu Malaterre [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
Remove version

Forwarded: not-needed
Bug-Debian: https://bugs.debian.org/1098944
Last-Update: 2025-03-21

Gbp-Pq: Name remove_version.patch

6 weeks agoDon't add executables to cmake exports
Gert Wollny [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
Don't add executables to cmake exports

Bug-Debian: https://bugs.debian.org/803304
Forwarded: not-needed

CMake exports are used by other packages that compile
and link against dcmtk. Because Debian moves some of
these executables and also dosn't install the test
executables, this import may fail leading to failure
to configure the according package.
===================================================================

Gbp-Pq: Name 07_dont_export_all_executables.patch

6 weeks agoThe original maintainer Jürgen Salk applied
Jürgen Salk [Thu, 11 Jun 2026 18:54:58 +0000 (20:54 +0200)]
The original maintainer Jürgen Salk applied

Forwarded: not-needed

a set of patches to the original code.  This file contains
changes to C++ code

Gbp-Pq: Name 01_dcmtk_3.6.0-1.patch

6 weeks ago0018-CVE-2026-10194.patch: new: fix CVE-2026-10194.
Étienne Mollier [Thu, 11 Jun 2026 18:54:21 +0000 (20:54 +0200)]
0018-CVE-2026-10194.patch: new: fix CVE-2026-10194.

Closes: #1139181
6 weeks ago0017-CVE-2025-14841.patch: new: fix CVE-2025-14841.
Étienne Mollier [Thu, 11 Jun 2026 18:51:34 +0000 (20:51 +0200)]
0017-CVE-2025-14841.patch: new: fix CVE-2025-14841.

Closes: #1123584
6 weeks ago0016-CVE-2026-5663.patch: new: fix CVE-2026-5663.
Étienne Mollier [Thu, 11 Jun 2026 18:47:58 +0000 (20:47 +0200)]
0016-CVE-2026-5663.patch: new: fix CVE-2026-5663.

Closes: #1133001
6 weeks ago0015-CVE-2025-14607.patch: new: fix CVE-2025-14607.
Étienne Mollier [Thu, 11 Jun 2026 18:40:33 +0000 (20:40 +0200)]
0015-CVE-2025-14607.patch: new: fix CVE-2025-14607.

Closes: #1122926
6 weeks agod/patches/*-CVE-2025-9732.patch: new.
Étienne Mollier [Thu, 11 Jun 2026 18:33:03 +0000 (20:33 +0200)]
d/patches/*-CVE-2025-9732.patch: new.

These changes pulled from dcmtk upstream address CVE-2025-9732.

Closes: #1113993
14 months agoMerge version 3.6.9-4+rpi1 and 3.6.9-5 to produce 3.6.9-5+rpi1 archive/raspbian/3.6.9-5+rpi1 raspbian/3.6.9-5+rpi1
Raspbian automatic forward porter [Thu, 1 May 2025 02:35:22 +0000 (03:35 +0100)]
Merge version 3.6.9-4+rpi1 and 3.6.9-5 to produce 3.6.9-5+rpi1

16 months agod/changelog: Upload 3.6.9-5 to unstable
Mathieu Malaterre [Fri, 21 Mar 2025 11:45:55 +0000 (12:45 +0100)]
d/changelog: Upload 3.6.9-5 to unstable

16 months agodocumentation: Spring cleanups. Closes: #1095639
Mathieu Malaterre [Fri, 21 Mar 2025 11:39:29 +0000 (12:39 +0100)]
documentation: Spring cleanups. Closes: #1095639

16 months ago0012-CVE-2025-2357.patch: new: fix CVE-2025-2357.
Mathieu Malaterre [Fri, 21 Mar 2025 11:38:06 +0000 (12:38 +0100)]
0012-CVE-2025-2357.patch: new: fix CVE-2025-2357.

Closes: #1100724
16 months agod/control: relax dependency on dcmtk-data. Closes: #1098944
Mathieu Malaterre [Fri, 21 Mar 2025 11:34:51 +0000 (12:34 +0100)]
d/control: relax dependency on dcmtk-data. Closes: #1098944

16 months agoFixed segfault in JPEG-LS decoder.
Marco Eichelberg [Mon, 3 Mar 2025 10:33:18 +0000 (11:33 +0100)]
Fixed segfault in JPEG-LS decoder.

X-Git-Url: http://git.dcmtk.org/?p=dcmtk.git;a=commitdiff_plain;h=3239a791542e1ea433d23aaa9e0a05a532ffabff;hp=92fc86e9e8d0808880bcc82e25982b2a61323cb8

Fixed segfault in JPEG-LS decoder.

Fixed a bug in the JPEG-LS decoder that led to a segmentation fault if invalid
input data was processed, due to insufficient validation of input data.

Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
and the sample file (PoC).

This closes DCMTK issue #1155.

Gbp-Pq: Name 0012-CVE-2025-2357.patch

16 months agoMerge dcmtk (3.6.9-5) import into refs/heads/workingbranch
Mathieu Malaterre [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Merge dcmtk (3.6.9-5) import into refs/heads/workingbranch

16 months agoCVE-2025-25472
Debian Med Packaging Team [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
CVE-2025-25472

commit 410ffe2019b9db6a8f4036daac742a6f5e4d36c2
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Fri Jan 17 17:53:50 2025 +0100

    Fixed another issue with invalid mono images.

    Fixed issue when rendering an invalid monochrome DICOM image where the
    number of pixels stored does not match the expected number of pixels.
    In this case, only a single pixel is processed, but the pixel matrix is
    much larger. Filling the rest of the pixel matrix with the smallest
    possible value for the image is not working because of an optimized
    memory usage (value would be out of range). Now, the pixel value to be
    used is double-checked before it is actually filled into the "background"
    of the image.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0011-CVE-2025-25472.patch

16 months agoFixed segfault in JPEG-LS decoder.
Marco Eichelberg [Mon, 3 Mar 2025 10:33:18 +0000 (11:33 +0100)]
Fixed segfault in JPEG-LS decoder.

X-Git-Url: http://git.dcmtk.org/?p=dcmtk.git;a=commitdiff_plain;h=3239a791542e1ea433d23aaa9e0a05a532ffabff;hp=92fc86e9e8d0808880bcc82e25982b2a61323cb8

Fixed segfault in JPEG-LS decoder.

Fixed a bug in the JPEG-LS decoder that led to a segmentation fault if invalid
input data was processed, due to insufficient validation of input data.

Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
and the sample file (PoC).

This closes DCMTK issue #1155.

Gbp-Pq: Name 0012-CVE-2025-2357.patch

16 months agoCVE-2025-25474
Debian Med Packaging Team [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
CVE-2025-25474

commit 1d205bcd307164c99e0d4bbf412110372658d847
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Tue Jan 21 11:12:28 2025 +0100

    Fixed another issue with invalid DICOM images.

    Fixed issue when processing an invalid DICOM image where the number of
    pixels stored does not match the expected number of pixels (too less)
    and the combination of BitsAllocated and BitsStored is really unusual
    (e.g. 1 bit stored, but 52 bits allocated). In cases where the last
    pixel (e.g. a single bit) does not fit into the buffer of the input
    pixel data, a buffer overflow occurred on the heap. Now, the last entry
    of the buffer is filled with the smallest possible value (e.g. 0 in case
    of unsigned data).

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0010-CVE-2025-25474.patch

16 months agoCVE-2025-25472
Debian Med Packaging Team [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
CVE-2025-25472

commit 410ffe2019b9db6a8f4036daac742a6f5e4d36c2
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Fri Jan 17 17:53:50 2025 +0100

    Fixed another issue with invalid mono images.

    Fixed issue when rendering an invalid monochrome DICOM image where the
    number of pixels stored does not match the expected number of pixels.
    In this case, only a single pixel is processed, but the pixel matrix is
    much larger. Filling the rest of the pixel matrix with the smallest
    possible value for the image is not working because of an optimized
    memory usage (value would be out of range). Now, the pixel value to be
    used is double-checked before it is actually filled into the "background"
    of the image.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0011-CVE-2025-25472.patch

16 months agoCVE-2025-25475
Debian Med Packaging Team [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
CVE-2025-25475

commit bffa3e9116abb7038b432443f16b1bd390e80245
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Thu Jan 23 15:51:21 2025 +0100

    Fixed issue with invalid RLE compressed DICOM images.

    Fixed issue when processing an RLE compressed image where the RLE header
    contains an invalid stripe size.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0009-CVE-2025-25475.patch

16 months agoCVE-2025-25474
Debian Med Packaging Team [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
CVE-2025-25474

commit 1d205bcd307164c99e0d4bbf412110372658d847
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Tue Jan 21 11:12:28 2025 +0100

    Fixed another issue with invalid DICOM images.

    Fixed issue when processing an invalid DICOM image where the number of
    pixels stored does not match the expected number of pixels (too less)
    and the combination of BitsAllocated and BitsStored is really unusual
    (e.g. 1 bit stored, but 52 bits allocated). In cases where the last
    pixel (e.g. a single bit) does not fit into the buffer of the input
    pixel data, a buffer overflow occurred on the heap. Now, the last entry
    of the buffer is filled with the smallest possible value (e.g. 0 in case
    of unsigned data).

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0010-CVE-2025-25474.patch

16 months agoAdded check to make sure: HighBit < BitsAllocated.
Joerg Riesmeier [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Added check to make sure: HighBit < BitsAllocated.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=03e851b0586d05057c3268988e180ffb426b2e03
Bug-Debian: https://bugs.debian.org/1093047
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Added check to the image preprocessing to make sure that the value of
HighBit is always less than the value of BitsAllocated. Before, this
missing check could lead to memory corruption if an invalid combination
of values was retrieved from a malformed DICOM dataset.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the report, sample file (PoC)
and detailed analysis. See TALOS-2024-2121 and CVE-2024-52333.

Gbp-Pq: Name 0008-CVE-2024-52333.patch

16 months agoCVE-2025-25475
Debian Med Packaging Team [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
CVE-2025-25475

commit bffa3e9116abb7038b432443f16b1bd390e80245
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Thu Jan 23 15:51:21 2025 +0100

    Fixed issue with invalid RLE compressed DICOM images.

    Fixed issue when processing an RLE compressed image where the RLE header
    contains an invalid stripe size.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0009-CVE-2025-25475.patch

16 months agoFixed issue rendering invalid monochrome image.
Joerg Riesmeier [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Fixed issue rendering invalid monochrome image.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6
Bug-Debian: https://bugs.debian.org/1093043
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Fixed issue when rendering an invalid monochrome DICOM image where the
number of pixels stored does not match the expected number of pixels.
If the stored number is less than the expected number, the rest of the
pixel matrix for the intermediate representation was always filled with
the value 0. Under certain, very rare conditions, this could result in
memory problems reported by an Address Sanitizer (ASAN). Now, the rest
of the matrix is filled with the smallest possible value for the image.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the original report, the sample
file (PoC) and further details. See TALOS-2024-2122 and CVE-2024-47796.

Gbp-Pq: Name 0007-CVE-2024-47796.patch

16 months agoAdded check to make sure: HighBit < BitsAllocated.
Joerg Riesmeier [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Added check to make sure: HighBit < BitsAllocated.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=03e851b0586d05057c3268988e180ffb426b2e03
Bug-Debian: https://bugs.debian.org/1093047
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Added check to the image preprocessing to make sure that the value of
HighBit is always less than the value of BitsAllocated. Before, this
missing check could lead to memory corruption if an invalid combination
of values was retrieved from a malformed DICOM dataset.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the report, sample file (PoC)
and detailed analysis. See TALOS-2024-2121 and CVE-2024-52333.

Gbp-Pq: Name 0008-CVE-2024-52333.patch

16 months agoRemove version
Mathieu Malaterre [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Remove version

Forwarded: not-needed
Bug-Debian: https://bugs.debian.org/1098944
Last-Update: 2025-03-21

Gbp-Pq: Name remove_version.patch

16 months agoFixed issue rendering invalid monochrome image.
Joerg Riesmeier [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Fixed issue rendering invalid monochrome image.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6
Bug-Debian: https://bugs.debian.org/1093043
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Fixed issue when rendering an invalid monochrome DICOM image where the
number of pixels stored does not match the expected number of pixels.
If the stored number is less than the expected number, the rest of the
pixel matrix for the intermediate representation was always filled with
the value 0. Under certain, very rare conditions, this could result in
memory problems reported by an Address Sanitizer (ASAN). Now, the rest
of the matrix is filled with the smallest possible value for the image.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the original report, the sample
file (PoC) and further details. See TALOS-2024-2122 and CVE-2024-47796.

Gbp-Pq: Name 0007-CVE-2024-47796.patch

16 months agoDon't add executables to cmake exports
Gert Wollny [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Don't add executables to cmake exports

Bug-Debian: https://bugs.debian.org/803304
Forwarded: not-needed

CMake exports are used by other packages that compile
and link against dcmtk. Because Debian moves some of
these executables and also dosn't install the test
executables, this import may fail leading to failure
to configure the according package.
===================================================================

Gbp-Pq: Name 07_dont_export_all_executables.patch

16 months agoRemove version
Mathieu Malaterre [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Remove version

Forwarded: not-needed
Bug-Debian: https://bugs.debian.org/1098944
Last-Update: 2025-03-21

Gbp-Pq: Name remove_version.patch

16 months agoThe original maintainer Jürgen Salk applied
Jürgen Salk [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
The original maintainer Jürgen Salk applied

Forwarded: not-needed

a set of patches to the original code.  This file contains
changes to C++ code

Gbp-Pq: Name 01_dcmtk_3.6.0-1.patch

16 months agoDon't add executables to cmake exports
Gert Wollny [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Don't add executables to cmake exports

Bug-Debian: https://bugs.debian.org/803304
Forwarded: not-needed

CMake exports are used by other packages that compile
and link against dcmtk. Because Debian moves some of
these executables and also dosn't install the test
executables, this import may fail leading to failure
to configure the according package.
===================================================================

Gbp-Pq: Name 07_dont_export_all_executables.patch

16 months agodcmtk (3.6.9-5) unstable; urgency=medium
Mathieu Malaterre [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
dcmtk (3.6.9-5) unstable; urgency=medium

  * d/control: relax dependency on dcmtk-data. Closes: #1098944
  * 0012-CVE-2025-2357.patch: new: fix CVE-2025-2357. (Closes: #1100724)
  * documentation: Spring cleanups. Closes: #1095639

[dgit import unpatched dcmtk 3.6.9-5]

16 months agoThe original maintainer Jürgen Salk applied
Jürgen Salk [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
The original maintainer Jürgen Salk applied

Forwarded: not-needed

a set of patches to the original code.  This file contains
changes to C++ code

Gbp-Pq: Name 01_dcmtk_3.6.0-1.patch

16 months agoImport dcmtk_3.6.9-5.debian.tar.xz
Mathieu Malaterre [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Import dcmtk_3.6.9-5.debian.tar.xz

[dgit import tarball dcmtk 3.6.9-5 dcmtk_3.6.9-5.debian.tar.xz]

16 months agodcmtk (3.6.9-5) unstable; urgency=medium
Mathieu Malaterre [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
dcmtk (3.6.9-5) unstable; urgency=medium

  * d/control: relax dependency on dcmtk-data. Closes: #1098944
  * 0012-CVE-2025-2357.patch: new: fix CVE-2025-2357. (Closes: #1100724)
  * documentation: Spring cleanups. Closes: #1095639

[dgit import unpatched dcmtk 3.6.9-5]

16 months agoImport dcmtk_3.6.9-5.debian.tar.xz
Mathieu Malaterre [Fri, 21 Mar 2025 11:45:44 +0000 (12:45 +0100)]
Import dcmtk_3.6.9-5.debian.tar.xz

[dgit import tarball dcmtk 3.6.9-5 dcmtk_3.6.9-5.debian.tar.xz]

16 months agoMerge version 3.6.8-6+rpi1 and 3.6.9-4 to produce 3.6.9-4+rpi1 archive/raspbian/3.6.9-4+rpi1 raspbian/3.6.9-4+rpi1
Raspbian automatic forward porter [Fri, 7 Mar 2025 04:12:06 +0000 (04:12 +0000)]
Merge version 3.6.8-6+rpi1 and 3.6.9-4 to produce 3.6.9-4+rpi1

17 months agod/changelog: ready for upload to unstable.
Étienne Mollier [Wed, 19 Feb 2025 21:31:16 +0000 (22:31 +0100)]
d/changelog: ready for upload to unstable.

17 months agoDeclare fast forward from 3.6.9-3
Étienne Mollier [Wed, 19 Feb 2025 21:30:57 +0000 (22:30 +0100)]
Declare fast forward from 3.6.9-3

[dgit --quilt=gbp --overwrite]

17 months agoCVE-2025-25472
Debian Med Packaging Team [Wed, 19 Feb 2025 21:30:57 +0000 (22:30 +0100)]
CVE-2025-25472

commit 410ffe2019b9db6a8f4036daac742a6f5e4d36c2
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Fri Jan 17 17:53:50 2025 +0100

    Fixed another issue with invalid mono images.

    Fixed issue when rendering an invalid monochrome DICOM image where the
    number of pixels stored does not match the expected number of pixels.
    In this case, only a single pixel is processed, but the pixel matrix is
    much larger. Filling the rest of the pixel matrix with the smallest
    possible value for the image is not working because of an optimized
    memory usage (value would be out of range). Now, the pixel value to be
    used is double-checked before it is actually filled into the "background"
    of the image.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0011-CVE-2025-25472.patch

17 months agoCVE-2025-25474
Debian Med Packaging Team [Wed, 19 Feb 2025 21:30:57 +0000 (22:30 +0100)]
CVE-2025-25474

commit 1d205bcd307164c99e0d4bbf412110372658d847
Author: Joerg Riesmeier <dicom@jriesmeier.com>
Date:   Tue Jan 21 11:12:28 2025 +0100

    Fixed another issue with invalid DICOM images.

    Fixed issue when processing an invalid DICOM image where the number of
    pixels stored does not match the expected number of pixels (too less)
    and the combination of BitsAllocated and BitsStored is really unusual
    (e.g. 1 bit stored, but 52 bits allocated). In cases where the last
    pixel (e.g. a single bit) does not fit into the buffer of the input
    pixel data, a buffer overflow occurred on the heap. Now, the last entry
    of the buffer is filled with the smallest possible value (e.g. 0 in case
    of unsigned data).

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0010-CVE-2025-25474.patch

17 months agoCVE-2025-25475
Debian Med Packaging Team [Wed, 19 Feb 2025 21:30:57 +0000 (22:30 +0100)]
CVE-2025-25475

commit bffa3e9116abb7038b432443f16b1bd390e80245
Author: Marco Eichelberg <eichelberg@offis.de>
Date:   Thu Jan 23 15:51:21 2025 +0100

    Fixed issue with invalid RLE compressed DICOM images.

    Fixed issue when processing an RLE compressed image where the RLE header
    contains an invalid stripe size.

    Thanks to Ding zhengzheng <xiaozheng.ding399@gmail.com> for the report
    and the sample file (PoC).

Gbp-Pq: Name 0009-CVE-2025-25475.patch

17 months agoAdded check to make sure: HighBit < BitsAllocated.
Joerg Riesmeier [Wed, 19 Feb 2025 21:30:57 +0000 (22:30 +0100)]
Added check to make sure: HighBit < BitsAllocated.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=03e851b0586d05057c3268988e180ffb426b2e03
Bug-Debian: https://bugs.debian.org/1093047
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Added check to the image preprocessing to make sure that the value of
HighBit is always less than the value of BitsAllocated. Before, this
missing check could lead to memory corruption if an invalid combination
of values was retrieved from a malformed DICOM dataset.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the report, sample file (PoC)
and detailed analysis. See TALOS-2024-2121 and CVE-2024-52333.

Gbp-Pq: Name 0008-CVE-2024-52333.patch

17 months agoFixed issue rendering invalid monochrome image.
Joerg Riesmeier [Wed, 19 Feb 2025 21:30:57 +0000 (22:30 +0100)]
Fixed issue rendering invalid monochrome image.

Forwarded: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=89a6e399f1e17d08a8bc8cdaa05b2ac9a50cd4f6
Bug-Debian: https://bugs.debian.org/1093043
Reviewed-By: Étienne Mollier <emollier@debian.org>
Last-Update: 2025-01-18

Fixed issue when rendering an invalid monochrome DICOM image where the
number of pixels stored does not match the expected number of pixels.
If the stored number is less than the expected number, the rest of the
pixel matrix for the intermediate representation was always filled with
the value 0. Under certain, very rare conditions, this could result in
memory problems reported by an Address Sanitizer (ASAN). Now, the rest
of the matrix is filled with the smallest possible value for the image.

Thanks to Emmanuel Tacheau from the Cisco Talos team
<vulndiscovery@external.cisco.com> for the original report, the sample
file (PoC) and further details. See TALOS-2024-2122 and CVE-2024-47796.

Gbp-Pq: Name 0007-CVE-2024-47796.patch

17 months agoRemove version
Mathieu Malaterre [Wed, 19 Feb 2025 21:30:57 +0000 (22:30 +0100)]
Remove version

Forwarded: not-needed
Last-Update: 2023-11-06

Gbp-Pq: Name remove_version.patch

17 months agoDon't add executables to cmake exports
Gert Wollny [Wed, 19 Feb 2025 21:30:57 +0000 (22:30 +0100)]
Don't add executables to cmake exports

Bug-Debian: https://bugs.debian.org/803304
Forwarded: not-needed

CMake exports are used by other packages that compile
and link against dcmtk. Because Debian moves some of
these executables and also dosn't install the test
executables, this import may fail leading to failure
to configure the according package.
===================================================================

Gbp-Pq: Name 07_dont_export_all_executables.patch

17 months agoThe original maintainer Jürgen Salk applied
Jürgen Salk [Wed, 19 Feb 2025 21:30:57 +0000 (22:30 +0100)]
The original maintainer Jürgen Salk applied

Forwarded: not-needed

a set of patches to the original code.  This file contains
changes to C++ code

Gbp-Pq: Name 01_dcmtk_3.6.0-1.patch

17 months ago0011-CVE-2025-25472.patch: new: fix CVE-2025-25472.
Étienne Mollier [Wed, 19 Feb 2025 21:30:36 +0000 (22:30 +0100)]
0011-CVE-2025-25472.patch: new: fix CVE-2025-25472.

17 months agod/changelog: unrelease.
Étienne Mollier [Wed, 19 Feb 2025 21:29:40 +0000 (22:29 +0100)]
d/changelog: unrelease.

17 months agod/changelog: ready for upload to unstable.
Étienne Mollier [Wed, 19 Feb 2025 20:57:06 +0000 (21:57 +0100)]
d/changelog: ready for upload to unstable.

17 months ago0010-CVE-2025-25474.patch: new: fix CVE-2025-25474.
Étienne Mollier [Wed, 19 Feb 2025 20:54:45 +0000 (21:54 +0100)]
0010-CVE-2025-25474.patch: new: fix CVE-2025-25474.

Closes: #1098374
17 months ago0009-CVE-2025-25475.patch: new: fix CVE-2025-25475.
Étienne Mollier [Wed, 19 Feb 2025 20:54:09 +0000 (21:54 +0100)]
0009-CVE-2025-25475.patch: new: fix CVE-2025-25475.

Closes: #1098373
17 months agoReinstate 0007-CVE-2024-47796.patch and 0008-CVE-2024-52333.patch.
Étienne Mollier [Wed, 19 Feb 2025 20:20:38 +0000 (21:20 +0100)]
Reinstate 0007-CVE-2024-47796.patch and 0008-CVE-2024-52333.patch.

These were not part of dcmtk 3.6.9 upstream and still apply.

Thanks: Salvatore Bonaccorso

17 months agod/changelog: Upload 3.6.9-3 to unstable
Mathieu Malaterre [Tue, 18 Feb 2025 11:05:49 +0000 (12:05 +0100)]
d/changelog: Upload 3.6.9-3 to unstable

17 months agoRecord dcmtk (3.6.9-3) in archive suite sid
Mathieu Malaterre [Tue, 18 Feb 2025 11:05:41 +0000 (12:05 +0100)]
Record dcmtk (3.6.9-3) in archive suite sid

Record that
  3.6.9-3              Import of source package
should be treated as descended from
  3.6.8-6              dgit client's archive history view

17 months agoRemove version
Mathieu Malaterre [Tue, 18 Feb 2025 11:05:41 +0000 (12:05 +0100)]
Remove version

Forwarded: not-needed
Last-Update: 2023-11-06

Gbp-Pq: Name remove_version.patch

17 months agoDon't add executables to cmake exports
Gert Wollny [Tue, 18 Feb 2025 11:05:41 +0000 (12:05 +0100)]
Don't add executables to cmake exports

Bug-Debian: https://bugs.debian.org/803304
Forwarded: not-needed

CMake exports are used by other packages that compile
and link against dcmtk. Because Debian moves some of
these executables and also dosn't install the test
executables, this import may fail leading to failure
to configure the according package.
===================================================================

Gbp-Pq: Name 07_dont_export_all_executables.patch

17 months agoThe original maintainer Jürgen Salk applied
Jürgen Salk [Tue, 18 Feb 2025 11:05:41 +0000 (12:05 +0100)]
The original maintainer Jürgen Salk applied

Forwarded: not-needed

a set of patches to the original code.  This file contains
changes to C++ code

Gbp-Pq: Name 01_dcmtk_3.6.0-1.patch

17 months agodcmtk (3.6.9-3) unstable; urgency=medium
Mathieu Malaterre [Tue, 18 Feb 2025 11:05:41 +0000 (12:05 +0100)]
dcmtk (3.6.9-3) unstable; urgency=medium

  * d/patches: Remove old unused patches
  * d/doc: Make sure to reference 3.6.9 path
  * d/watch: Properly watch upstream on github

[dgit import unpatched dcmtk 3.6.9-3]

17 months agoImport dcmtk_3.6.9-3.debian.tar.xz
Mathieu Malaterre [Tue, 18 Feb 2025 11:05:41 +0000 (12:05 +0100)]
Import dcmtk_3.6.9-3.debian.tar.xz

[dgit import tarball dcmtk 3.6.9-3 dcmtk_3.6.9-3.debian.tar.xz]

17 months agod/watch: Properly watch upstream on github
Mathieu Malaterre [Tue, 18 Feb 2025 11:05:01 +0000 (12:05 +0100)]
d/watch: Properly watch upstream on github

17 months agod/doc: Make sure to reference 3.6.9 path
Mathieu Malaterre [Tue, 18 Feb 2025 11:03:39 +0000 (12:03 +0100)]
d/doc: Make sure to reference 3.6.9 path

17 months agod/patches: Remove old unused patches
Mathieu Malaterre [Tue, 18 Feb 2025 11:03:04 +0000 (12:03 +0100)]
d/patches: Remove old unused patches

17 months agod/changelog: Upload 3.6.9-2 to experimental
Mathieu Malaterre [Tue, 11 Feb 2025 07:12:57 +0000 (08:12 +0100)]
d/changelog: Upload 3.6.9-2 to experimental

17 months agod/t/run-unit-test: Adapt to new installation
Mathieu Malaterre [Tue, 11 Feb 2025 07:08:43 +0000 (08:08 +0100)]
d/t/run-unit-test: Adapt to new installation

17 months agod/changelog: Upload 3.6.9-1 to experimental
Mathieu Malaterre [Thu, 30 Jan 2025 12:17:16 +0000 (13:17 +0100)]
d/changelog: Upload 3.6.9-1 to experimental