Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 42: dcmtk 2025-22c8d5a1c7 Security Advisory Updates

fedora
Calendar Grey March 15, 2025
Dist Fedora Esm H88
Security advisory for Fedora 42 addresses critical dcmkt vulnerabilities CVE-2024-27628 and CVE-2024-28130 with needed fixes.
Update for dcmtk 3.6.9 Includes security fix for CVE-2024-27628, CVE-2024-28130

Summary

DCMTK is a collection of libraries and applications implementing large

parts the DICOM standard. It includes software for examining,

constructing and converting DICOM image files, handling offline media,

sending and receiving images over a network connection, as well as

demonstrative image storage and worklist servers. DCMTK is is written

in a mixture of ANSI C and C++. It comes in complete source code and

is made available as "open source" software. This package includes

multiple fixes taken from the "patched DCMTK" project.

Install DCMTK if you are working with DICOM format medical image files.

Update Information:

Update for dcmtk 3.6.9 Includes security fix for CVE-2024-27628, CVE-2024-28130

Change Log

* Thu Feb 20 2025 Ankur Sinha - 3.6.9-2 - Update license to SPDX identifiers * Mon Feb 10 2025 Ankur Sinha - 3.6.9-1 - Update to 3.6.9 (rh#2297944)

References


[ 1 ] Bug #2293952 - CVE-2024-28130 dcmtk: incorrect type conversion https://bugzilla.redhat.com/show_bug.cgi?id=2293952 [ 2 ] Bug #2294757 - CVE-2024-27628 dcmtk: Buffer Overflow via the EctEnhancedCT method https://bugzilla.redhat.com/show_bug.cgi?id=2294757

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-22c8d5a1c7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: dcmtk
Product: Fedora 42
Version: 3.6.9
Release: 2.fc42
Summary: Offis DICOM Toolkit (DCMTK)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here