-------------------------------------------------------------------------
Debian LTS Advisory DLA-4443-1                [email protected]
https://www.debian.org/lts/security/                      Markus Koschany
January 19, 2026                              https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package        : dcmtk
Version        : 3.6.5-1+deb11u6
CVE ID         : CVE-2025-14607 CVE-2025-14841
Debian Bug     : 1122926 1123584

Two vulnerabilities have been addressed in DCMTK, a collection of
libraries and applications implementing large parts of the DICOM standard
for medical images.

CVE-2025-14607

    Possible memory corruption caused by illegal attributes in datasets which
    are processed by DcmByteString functions.

CVE-2025-14841

    Invalid messages sent to dcmqrscp, the Image Central Test Node, may
    trigger a segmentation fault due to a NULL pointer being de-referenced. 

For Debian 11 bullseye, these problems have been fixed in version
3.6.5-1+deb11u6.

We recommend that you upgrade your dcmtk packages.

For the detailed security status of dcmtk please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/dcmtk

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to