Package: dcmtk Version: 3.6.5-1 Severity: important Dear Maintainer,
Multiples CVEs have been reported against DCMTK: - CVE-2022-2119 - CVE-2022-2120 - CVE-2022-2121 Should we track them ? Should it be handled by debian-security team ? -- System Information: Debian Release: 11.3 APT prefers stable-updates APT policy: (500, 'stable-updates'), (500, 'stable-security'), (500, 'stable-debug'), (500, 'proposed-updates-debug'), (500, 'stable') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 5.10.0-15-amd64 (SMP w/8 CPU threads) Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, TAINT_UNSIGNED_MODULE Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US:en Shell: /bin/sh linked to /usr/bin/dash Init: systemd (via /run/systemd/system) LSM: AppArmor: enabled Versions of packages dcmtk depends on: ii adduser 3.118 ii libc6 2.31-13+deb11u3 ii libdcmtk17 3.6.7-5 ii libgcc-s1 10.2.1-6 ii libstdc++6 10.2.1-6 ii libxml2 2.9.10+dfsg-6.7+deb11u2 ii zlib1g 1:1.2.11.dfsg-2+deb11u1 dcmtk recommends no packages. dcmtk suggests no packages. -- no debconf information

