Source: dcmtk
Version: 3.7.0+really3.7.0-5
Severity: important
Tags: security upstream
Forwarded: https://support.dcmtk.org/redmine/issues/1208
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for dcmtk.

CVE-2026-12805[0]:
| A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected
| element is the function XMLNode::parseFile in the library
| ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-
| based buffer overflow. The attack may be performed from remote. The
| exploit has been published and may be used. This patch is called
| 1d4b3815c0987840a983160bfc671fef63a3105b. It is best practice to
| apply a patch to resolve this issue. The vendor was contacted early,
| responded in a very professional manner and quickly released a fixed
| version of the affected product.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-12805
    https://www.cve.org/CVERecord?id=CVE-2026-12805
[1] https://support.dcmtk.org/redmine/issues/1208
[2] 
https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=1d4b3815c0987840a983160bfc671fef63a3105b

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to