openSUSE-SU-2025:0068-1: important: Security update for dcmtk

openSUSE Security Update: Security update for dcmtk ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0068-1 Rating: important References: #1237355 #1237365 #1237369 Cross-References: CVE-2025-25472 CVE-2025-25474 CVE-2025-25475 CVSS scores: CVE-2025-25472 (SUSE): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVE-2025-25474 (SUSE): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N CVE-2025-25475 (SUSE): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for dcmtk fixes the following issues: - CVE-2025-25472: Fixed a denial of service via a crafted DCM file (boo#1237369). - CVE-2025-25474: Fixed a denial of service via a crafted DICOM file (boo#1237365). - CVE-2025-25475: Fixed a buffer overflow via the component /dcmimgle/diinpxt.h (boo#1237355). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-68=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): dcmtk-3.6.9-bp156.4.6.1 dcmtk-devel-3.6.9-bp156.4.6.1 libdcmtk19-3.6.9-bp156.4.6.1 References: https://www.suse.com/security/cve/CVE-2025-25472.html https://www.suse.com/security/cve/CVE-2025-25474.html https://www.suse.com/security/cve/CVE-2025-25475.html https://bugzilla.suse.com/1237355 https://bugzilla.suse.com/1237365 https://bugzilla.suse.com/1237369
participants (1)
-
opensuse-security@opensuse.org