[Git][security-tracker-team/security-tracker][master] Add new dcmtk issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jul 4 08:26:55 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9c32d713 by Salvatore Bonaccorso at 2026-07-04T09:26:17+02:00
Add new dcmtk issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2116,7 +2116,8 @@ CVE-2026-54500 (Oj (Optimized JSON) is a JSON parser and Object marshaller packa
 	- ruby-oj 3.17.3-1
 	NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-fm7p-mprw-wjm9
 CVE-2026-52868 (An unauthenticated attacker can read worklist records from a directory ...)
-	TODO: check
+	- dcmtk <unfixed>
+	NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=e3878daf870cd2db50eadfde38615f0afae8a584
 CVE-2026-52198 (Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-1613 ...)
 	NOT-FOR-US: UTT
 CVE-2026-52197 (An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote at ...)
@@ -2128,15 +2129,19 @@ CVE-2026-52195 (Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-21091
 CVE-2026-52193 (Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-1613 ...)
 	NOT-FOR-US: UTT
 CVE-2026-50254 (An unauthenticated remote attacker can repeatedly send a single crafte ...)
-	TODO: check
+	- dcmtk <unfixed>
+	NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=23f181f7a3cb8334056f751a3a0c2ddf01046752
 CVE-2026-50110 (Storage Concentrator (SC & SCVM) contains hardcoded credentials for nu ...)
 	NOT-FOR-US: Storage Concentrator
 CVE-2026-50040 (Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site ...)
 	NOT-FOR-US: Storage Concentrator
 CVE-2026-50003 (A malicious or compromised server can make a DCMTK client using bit-pr ...)
-	TODO: check
+	- dcmtk <unfixed>
+	NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=eca9a03dda7d4fc1faa7e5a6dac9617938cf5803
 CVE-2026-44628 (An unauthenticated attacker can crash the worklist server with a singl ...)
-	TODO: check
+	- dcmtk <unfixed>
+	NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=f4e0074682645b1a4289d62581926c4394d5c6d5
+	NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=694a0a06a38015ce768fa161a62b148189f84959
 CVE-2026-44042 (UltraVNC repeater through 1.8.2.2 contains an off-by-one error in the  ...)
 	NOT-FOR-US: UltraVNC
 CVE-2026-44041 (UltraVNC through 1.8.2.2 contains an out-of-bounds read in the wide-st ...)
@@ -2149,7 +2154,8 @@ CVE-2026-37106 (An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remot
 	NOTE: Bogus CVE assignment for DokuWiki
 	NOTE: https://github.com/dokuwiki/dokuwiki/issues/4682
 CVE-2026-35505 (An unauthenticated remote attacker can repeatedly send crafted connect ...)
-	TODO: check
+	- dcmtk <unfixed>
+	NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=2312891a8d058c862e00bcbd636e5da26308658a
 CVE-2026-2387 (The Event Organiser plugin for WordPress is vulnerable to Stored Cross ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-28322 (SolarWinds Database Performance Analyzer was found to be affected by a ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9c32d713e101cf0685c6b82d4bc6c60b04ad4756

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9c32d713e101cf0685c6b82d4bc6c60b04ad4756
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260704/e610d6af/attachment.htm>


More information about the debian-security-tracker-commits mailing list