-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 20 Feb 2025 21:59:03 +0100 Source: dcmtk Binary: dcmtk-doc Architecture: all Version: 3.6.7-9~deb12u3 Distribution: bookworm Urgency: medium Maintainer: all Build Daemon (x86-csail-02) Changed-By: Étienne Mollier Description: dcmtk-doc - OFFIS DICOM toolkit documentation Closes: 1070207 1098373 1098374 Changes: dcmtk (3.6.7-9~deb12u3) bookworm; urgency=medium . * Team upload. * Introduce patch series to fix CVE-2024-28130. This change introduces the patches: * 0001-Fixed-unchecked-typecasts-of-DcmItem-search-results.patch * 0002-Fixed-unchecked-typecasts-and-fixed-LUT-handling.patch * 0003-Fixed-wrong-error-handling-previous-commit.patch mapping to upstream commits: * dc6a2446dc03c9db90f82ce17a597f2cd53776c5 * 601b227eecaab33a3a3a11dc256d84b1a62f63af * 7d54f8efec995e5601d089fa17b0625c2b41af23 with the nuance that upstream check functions are inlined, in order to avoid an ABI breakage. Thanks to Adrian Bunk (Closes: #1070207) * 0009-CVE-2025-25475.patch: new: fix CVE-2025-25475. (Closes: #1098373) * 0010-CVE-2025-25474.patch: new: fix CVE-2025-25474. (Closes: #1098374) * 0011-CVE-2025-25472.patch: new: fix CVE-2025-25472. Checksums-Sha1: f3712cab83245f95efb45236af4bacd02d2e6084 7986664 dcmtk-doc_3.6.7-9~deb12u3_all.deb 67e851cf7c53324dc2814f7570effc413a7d95ca 9796 dcmtk_3.6.7-9~deb12u3_all-buildd.buildinfo Checksums-Sha256: baad61fd55881e3e93ec44992e9a10c924b98ad4caacadba0975fa8a9efd75e5 7986664 dcmtk-doc_3.6.7-9~deb12u3_all.deb f57bf555a0b10a857109fd423e0608ea42e08073de629a4eb73f96ba81c7e290 9796 dcmtk_3.6.7-9~deb12u3_all-buildd.buildinfo Files: 9fe3c4d59968dc01dd6f927bec9dcc6a 7986664 doc optional dcmtk-doc_3.6.7-9~deb12u3_all.deb e08f20a45ddaebc55e5f69cfb4947c8f 9796 science optional dcmtk_3.6.7-9~deb12u3_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEzcbx6nIE/ydHa1FFigL77i1GSVkFAmfMrDwACgkQigL77i1G SVkLag/+Niizg4A8XU7PvwMu9/h+wJUt4QGuuc11C7EkSHEx9IiqJarY+jlaXycz h2d5BSK1l/tVVF16KRWQ3JlGKzAmyW9nfLQ5DarCIqiQ12d5d3AudrLlPv+ucczg fGBscDEhm80Og9fL4v38+5wwEjzrrEiNlolVqc/uXocgJ9CyF7G1LXFSUkO4L+zx R3UYS/sPTPs0ejFYvOqDhSOm/Zw4Hvut5YT2YhXwkAFx748MPqN8ctdM+HJvARLb Py6knc6iXbAT9vPOy5vXb9Y38Tla3RdfJZt1LASyiU2q6Y3yfRw2Y/1SAobz7+ba BdmlUulYLlCBoHaCfZnxGKfGCh6APkBZOL8vSDp0KJCdPtbE7NelnsGpBpKyC23N qJMvuYGQ8lHsNXE2T4mhb1TAZSL9IF3iNwcGegiofpfuuTOx6H9kzMb5twv92foZ 35TLs2Nn75M2qMeudfOaLwKBCu0j1684FUNTEMF4kO56rvONTVqlzYqDm/fjss5f 6erEcyjWM3O0Su6L8gllQPnTdR/McjDsZV7r9w9jmeNQDZJW+mS01UXBw26D+wDc GFbIt7eFic1cLOxpVqHCSDk77qkUg5FzMHJmLq2v/z+jjFRP2q0nrsoFaTSwRhW2 rnkVw+8eeh9sKzdGer2LwhOcWaFAq83kkoH71rfQPNEfTYmknf0= =rvX3 -----END PGP SIGNATURE-----