Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE: 2022:10145-1 Critical: GDCM And Orthanc Security Issues

opensuse
Calendar Grey October 12, 2022
Dist Opensuse Esm H88
Tackling pressing concerns in gdcm, orthanc, and associated tools through this vital openSUSE security patch.
An update that fixes two vulnerabilities is now available

Description

This update for gdcm, orthanc, orthanc-gdcm, orthanc-webviewer fixes the

following issues:

Changes in gdcm:

- rename of gdcm-libgdcm3_0 to libgdcm3_0 (proposal S. Br??ns)

- version 3.0.18

no changelog

- version 3.0.12

* support for poppler 22.03 added

Changes in orthanc-gdcm:

- changed dependency gdcm-libgdcm3_0 -> libgdcm3_0

Changes in orthanc:

- version 1.11.2

* Added support for RGBA64 images in tools/create-dicom and /preview

* New configuration "MaximumStorageMode" to choose between recyling of

old patients (default behavior) and rejection of new incoming data

when the MaximumStorageSize has been reached.

* New sample plugin: "DelayedDeletion" that will delete files from disk

asynchronously to speed up deletion of large studies.

* Lua: new "SetHttpTimeout" function

* Lua: new "OnHeartBeat" callback called at regular interval provided

that you have configured...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2022-10145=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 ppc64le s390x x86_64):

gdcm-3.0.19-bp154.2.5.1

gdcm-applications-3.0.19-bp154.2.5.1

gdcm-applications-debuginfo-3.0.19-bp154.2.5.1

gdcm-debuginfo-3.0.19-bp154.2.5.1

gdcm-debugsource-3.0.19-bp154.2.5.1

gdcm-devel-3.0.19-bp154.2.5.1

gdcm-examples-3.0.19-bp154.2.5.1

libgdcm3_0-3.0.19-bp154.2.5.1

libgdcm3_0-debuginfo-3.0.19-bp154.2.5.1

libsocketxx1_2-3.0.19-bp154.2.5.1

libsocketxx1_2-debuginfo-3.0.19-bp154.2.5.1

orthanc-gdcm-1.5-bp154.2.3.1

orthanc-gdcm-debuginfo-1.5-bp154.2.3.1

orthanc-gdcm-debugsource-1.5-bp154.2.3.1

orthanc-webviewer-2.8-bp154.2.3.1

orthanc-webviewer-debuginfo-2.8-bp154.2.3.1

orthanc-webviewer-debugsource-2.8-bp154.2.3.1

python3-gdcm-3.0.19-bp154.2.5.1

python3-gdcm-debuginfo-3.0.19-bp154.2.5.1

- openSUSE Backports SLE-15-SP4 (aarch64 ppc64le x86_64):

orthanc-1.11.2-bp154.2.3.1

orthanc-debuginfo-1.11.2-bp154.2.3.1

orthanc-debugsource-1.11.2-bp154.2.3.1

orthanc-devel-1.11.2-bp154.2.3.1

orthanc-source-1.11.2-bp154.2.3.1

- openSUSE Backports SLE-15-SP4...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2022-2119.html

https://www.suse.com/security/cve/CVE-2022-2120.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:10145-1
Rating: important
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here