Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE: 2023:0110-1 Important: xyzlib Security Vulnerability Addressed

opensuse
Calendar Grey May 15, 2023
Dist Opensuse Esm H88
A critical Fedora patch for dcmtk resolves multiple security issues. Discover the details of the fixes and the steps to apply the updates.
An update that fixes four vulnerabilities is now available

Description

This update for dcmtk fixes the following issues:

- CVE-2022-43272: Fixed memory leak via the T_ASC_Association object

(boo#1206070)

- Update to 3.6.7 (boo#1208639, boo#1208638, boo#1208637, CVE-2022-2121,

CVE-2022-2120, CVE-2022-2119)

- CVE-2022-2121: Fixed possible DoS via NULL pointer dereference

- CVE-2022-2120: Fixed relative path traversal vulnerability

- CVE-2022-2119: Fixed path traversal vulnerability

See DOCS/CHANGES.367 for the full list of changes

* Updated code definitions for DICOM 2022b

* Fixed possible NULL pointer dereference

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2023-108=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64):

dcmtk-3.6.7-bp154.2.3.1

dcmtk-devel-3.6.7-bp154.2.3.1

libdcmtk17-3.6.7-bp154.2.3.1

References

https://www.suse.com/security/cve/CVE-2022-2119.html

https://www.suse.com/security/cve/CVE-2022-2120.html

https://www.suse.com/security/cve/CVE-2022-2121.html

https://www.suse.com/security/cve/CVE-2022-43272.html

https://bugzilla.suse.com/1206070

https://bugzilla.suse.com/1208637

https://bugzilla.suse.com/1208638

https://bugzilla.suse.com/1208639

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2023:0108-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here