Bug 34043 - dcmtk new security issues CVE-2025-2547[245]
Summary: dcmtk new security issues CVE-2025-2547[245]
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-02-24 16:34 CET by Nicolas Salguero
Modified: 2025-02-25 22:41 CET (History)
3 users (show)

See Also:
Source RPM: dcmtk-3.6.9-1.mga10.src.rpm, dcmtk-3.6.7-4.3.mga9.src.rpm
CVE: CVE-2025-25472, CVE-2025-25474, CVE-2025-25475
Status comment: Patches available from upstream and openSUSE


Attachments

Description Nicolas Salguero 2025-02-24 16:34:55 CET
openSUSE has issued an advisory on February 21:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/VEIE5K5WMSCBUU2JDXY5E576NA36I3NC/
Comment 1 Nicolas Salguero 2025-02-24 16:36:24 CET
Fixes:
https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=bffa3e9116abb7038b432443f16b1bd390e80245
https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=1d205bcd307164c99e0d4bbf412110372658d847
https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=410ffe2019b9db6a8f4036daac742a6f5e4d36c2

CVE: (none) => CVE-2025-25472, CVE-2025-25474, CVE-2025-25475
Status comment: (none) => Patches available from upstream and openSUSE
Source RPM: (none) => dcmtk-3.6.9-1.mga10.src.rpm, dcmtk-3.6.7-4.3.mga9.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 2 Lewis Smith 2025-02-24 21:33:51 CET
Thanks for the patch URLs.
Assigning directly to DavidG, who normally updates this SRPM.

Assignee: bugsquad => geiger.david68210

Comment 3 David GEIGER 2025-02-25 07:04:08 CET
Fixed both mga9 and Cauldron!


Packages in 9/Core/Updates_testing repo:
=========================
dcmtk-3.6.7-4.4.mga9
libdcmtk-devel-3.6.7-4.4.mga9
libdcmtk17-3.6.7-4.4.mga9
lib64dcmtk-devel-3.6.7-4.4.mga9
lib64dcmtk17-3.6.7-4.4.mga9


From SRPMS
dcmtk-3.6.7-4.4.mga9.src.rpm

Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9
Assignee: geiger.david68210 => qa-bugs

Comment 4 Herman Viaene 2025-02-25 15:41:06 CET
MGA9-64 Plasma Wayland on Compaq H000SB
No installation issues.
Ref bug 33930 for testing.
Used olive-editor, importing small mpg file, plays OK, larger mpg file plays, but sounfd lags some 5 seconds behind. This is anolder laptop, so I'm not that surprised. Opened avi file which has no sound: plays OK.
Fiddled a bit with blender: no problems seen.
Dood to go AFAICS.

Whiteboard: (none) => MGA9-64-OK
CC: (none) => herman.viaene

Comment 5 Thomas Andrews 2025-02-25 15:56:20 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

katnatek 2025-02-25 20:37:50 CET

Keywords: (none) => advisory

Comment 6 Mageia Robot 2025-02-25 22:41:40 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0076.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.