openSUSE has issued an advisory on November 22: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/U3LXLFP2Q7LBLGBNWEPO3O2ZZ2JPCYEU/ Fix: https://github.com/DCMTK/dcmtk/commit/ec52e99e1e33fc39810560421c0833b02da567b3
Source RPM: (none) => dcmtk-3.6.8-2.mga10.src.rpm, dcmtk-3.6.7-4.1.mga9.src.rpmStatus comment: (none) => Patch available from upstream ans openSUSEWhiteboard: (none) => MGA9TOOCVE: (none) => CVE-2024-27628
Status comment: Patch available from upstream ans openSUSE => Patch available from upstream and openSUSE
Cauldron already contains this upstream patch: Patch2: 0001-Fixed-possible-overflows-when-allocating-memory.patch
Whiteboard: MGA9TOO => (none)Version: Cauldron => 9CC: (none) => geiger.david68210
Suggested advisory: ======================== The updated packages fix a security vulnerability: Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component. (CVE-2024-27628) References: https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/U3LXLFP2Q7LBLGBNWEPO3O2ZZ2JPCYEU/ ======================== Updated packages in core/updates_testing: ======================== dcmtk-3.6.7-4.2.mga9 lib(64)dcmtk17-3.6.7-4.2.mga9 lib(64)dcmtk-devel-3.6.7-4.2.mga9 from SRPM: dcmtk-3.6.7-4.2.mga9.src.rpm
Source RPM: dcmtk-3.6.8-2.mga10.src.rpm, dcmtk-3.6.7-4.1.mga9.src.rpm => dcmtk-3.6.7-4.1.mga9.src.rpmStatus: NEW => ASSIGNEDStatus comment: Patch available from upstream and openSUSE => (none)Assignee: bugsquad => qa-bugs
Keywords: (none) => advisory
RH x86_64 installing lib64dcmtk17-3.6.7-4.2.mga9.x86_64.rpm dcmtk-3.6.7-4.2.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/2: lib64dcmtk17 ################################################################################################## 2/2: dcmtk ################################################################################################## 1/2: removing dcmtk-3.6.7-4.1.mga9.x86_64 ################################################################################################## 2/2: removing lib64dcmtk17-3.6.7-4.1.mga9.x86_64 ################################################################################################## strace blender shows openat(AT_FDCWD, "/lib64/libdcmimage.so.17", O_RDONLY|O_CLOEXEC) = 3 openat(AT_FDCWD, "/lib64/libdcmimgle.so.17", O_RDONLY|O_CLOEXEC) = 3 openat(AT_FDCWD, "/lib64/libdcmdata.so.17", O_RDONLY|O_CLOEXEC) = 3
Whiteboard: (none) => MGA9-64-OKCC: (none) => andrewsfarm
Validating.
Keywords: (none) => validated_updateCC: (none) => sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0380.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED