<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for gdcm, orthanc, orthanc-gdcm, orthanc-webviewer</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2022:10144-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2022-10-12T15:35:18Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2022-10-12T15:35:18Z</InitialReleaseDate>
    <CurrentReleaseDate>2022-10-12T15:35:18Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for gdcm, orthanc, orthanc-gdcm, orthanc-webviewer</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for gdcm, orthanc, orthanc-gdcm, orthanc-webviewer fixes the following issues:

Changes in gdcm:

- Provides/obsoletes moved to lbgdcm-package (Thx DimStar)
- rename of gdcm-libgdcm3_0 to libgdcm3_0 (proposal S. Brüns)

- version 3.0.18

  no changelog

- version 3.0.12

  * support for poppler 22.03 added

- version 3.0.11

  * Fix for a significant issue with JPEG-LS and RGB color space
  * tons of small bug fixes

- version 3.0.10 (no changelog)

Changes in orthanc-gdcm:

- changed dependency gdcm-libgdcm3_0 -&gt; libgdcm3_0

- Version 1.5 

* Take the configuration option 'RestrictTransferSyntaxes' into
  account not only for decoding, but also for transcoding
* Upgrade to GDCM 3.0.10 for static builds- 

Changes in orthanc:

- version 1.11.2
  * Added support for RGBA64 images in tools/create-dicom and /preview
  * New configuration 'MaximumStorageMode' to choose between recyling of
    old patients (default behavior) and rejection of new incoming data when
    the MaximumStorageSize has been reached.
  * New sample plugin: 'DelayedDeletion' that will delete files from disk
    asynchronously to speed up deletion of large studies.
  * Lua: new 'SetHttpTimeout' function
  * Lua: new 'OnHeartBeat' callback called at regular interval provided that
       you have configured 'LuaHeartBeatPeriod' &gt; 0.
  * 'ExtraMainDicomTags' configuration now accepts Dicom Sequences.  Sequences are
    stored in a dedicated new metadata 'MainDicomSequences'.  This should improve
    DicomWeb QIDO-RS and avoid warnings like 'Accessing Dicom tags from storage when 
    accessing series : 0040,0275'.
    Main dicom sequences can now be returned in 'MainDicomTags' and in 'RequestedTags'.
  * Fix the 'Never' option of the 'StorageAccessOnFind' that was sill accessing
    files (bug introduced in 1.11.0).
  * Fix the Storage Cache for compressed files (bug introduced in 1.11.1).
  * Fix the storage cache that was not used by the Plugin SDK.  This fixes the 
    DicomWeb plugin '/rendered' route performance issues.
  * DelayedDeletion plugin: Fix leaking of symbols
  * SQLite now closes and deletes WAL and SHM files on exit.  This should improve
    handling of SQLite DB over network drives.
  * Fix static compilation of boost 1.69 on Ubuntu 22.04
  * Upgraded dependencies for static builds:
    - boost 1.80.0
    - dcmtk 3.6.7  (fixes CVE-2022-2119 and CVE-2022-2120)
    - openssl 3.0.5
  * Housekeeper plugin: Fix resume of previous processing
  * Added missing MOVEPatientRootQueryRetrieveInformationModel in 
    DicomControlUserConnection::SetupPresentationContexts()
  * Improved HttpClient error logging (add method + url)
  * API version upgraded to 18
  * /system is now reporting 'DatabaseServerIdentifier'
  * Added an Asynchronous mode to /modalities/../move.
  * 'RequestedTags' option can now include DICOM sequences.
  * New function in the SDK: 'OrthancPluginGetDatabaseServerIdentifier'
  * DicomMap::ParseMainDicomTags has been deprecated -&gt; retrieve 'full' tags
    and use DicomMap::FromDicomAsJson instead

- version 1.11.0

* new API version 1.7
* new configuration parameter
* for detailed changelog see NEWS

- version 1.10.1

* for detailed changelog see NEWS

- Version 1.9.7

* New configuration option 'DicomAlwaysAllowMove' to disable verification of
  the remote modality in C-MOVE SCP
* API version upgraded to 15
* Added 'Level' option to POST /tools/bulk-modify
* Added missing OpenAPI documentation of 'KeepSource' in '.../modify' and '.../anonymize'
* Added file CITATION.cff
* Linux Standard Base (LSB) builds of Orthanc can load non-LSB builds of plugins
* Fix upload of ZIP archives containing a DICOMDIR file
* Fix computation of the estimated time of arrival in jobs
* Support detection of windowing and rescale in Philips multiframe images 

Changes in orthanc-webviewer:

- version 2.8
  * Fix XSS inside DICOM in Orthanc Web Viewer (as reported by Stuart
    Kurutac, NCC Group)
  * framework190.diff removed (covered in actual version)  
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2022-10144</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K67WDY4JVASQKGAJHGMCE45SJSPPFKPM/</URL>
      <Description>E-Mail link for openSUSE-SU-2022:10144-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181400</URL>
      <Description>SUSE Bug 1181400</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-2119/</URL>
      <Description>SUSE CVE CVE-2022-2119 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-2120/</URL>
      <Description>SUSE CVE CVE-2022-2120 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Package Hub 15 SP3">
      <Branch Type="Product Name" Name="SUSE Package Hub 15 SP3">
        <FullProductName ProductID="SUSE Package Hub 15 SP3">SUSE Package Hub 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.3">
      <Branch Type="Product Name" Name="openSUSE Leap 15.3">
        <FullProductName ProductID="openSUSE Leap 15.3" CPE="cpe:/o:opensuse:leap:15.3">openSUSE Leap 15.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="gdcm-3.0.19-bp153.2.8.1">
      <FullProductName ProductID="gdcm-3.0.19-bp153.2.8.1">gdcm-3.0.19-bp153.2.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gdcm-applications-3.0.19-bp153.2.8.1">
      <FullProductName ProductID="gdcm-applications-3.0.19-bp153.2.8.1">gdcm-applications-3.0.19-bp153.2.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gdcm-devel-3.0.19-bp153.2.8.1">
      <FullProductName ProductID="gdcm-devel-3.0.19-bp153.2.8.1">gdcm-devel-3.0.19-bp153.2.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gdcm-examples-3.0.19-bp153.2.8.1">
      <FullProductName ProductID="gdcm-examples-3.0.19-bp153.2.8.1">gdcm-examples-3.0.19-bp153.2.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgdcm3_0-3.0.19-bp153.2.8.1">
      <FullProductName ProductID="libgdcm3_0-3.0.19-bp153.2.8.1">libgdcm3_0-3.0.19-bp153.2.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsocketxx1_2-3.0.19-bp153.2.8.1">
      <FullProductName ProductID="libsocketxx1_2-3.0.19-bp153.2.8.1">libsocketxx1_2-3.0.19-bp153.2.8.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-1.11.2-bp153.2.13.1">
      <FullProductName ProductID="orthanc-1.11.2-bp153.2.13.1">orthanc-1.11.2-bp153.2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-devel-1.11.2-bp153.2.13.1">
      <FullProductName ProductID="orthanc-devel-1.11.2-bp153.2.13.1">orthanc-devel-1.11.2-bp153.2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-doc-1.11.2-bp153.2.13.1">
      <FullProductName ProductID="orthanc-doc-1.11.2-bp153.2.13.1">orthanc-doc-1.11.2-bp153.2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-gdcm-1.5-bp153.2.6.1">
      <FullProductName ProductID="orthanc-gdcm-1.5-bp153.2.6.1">orthanc-gdcm-1.5-bp153.2.6.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-source-1.11.2-bp153.2.13.1">
      <FullProductName ProductID="orthanc-source-1.11.2-bp153.2.13.1">orthanc-source-1.11.2-bp153.2.13.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-webviewer-2.8-bp153.2.3.1">
      <FullProductName ProductID="orthanc-webviewer-2.8-bp153.2.3.1">orthanc-webviewer-2.8-bp153.2.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-gdcm-3.0.19-bp153.2.8.1">
      <FullProductName ProductID="python3-gdcm-3.0.19-bp153.2.8.1">python3-gdcm-3.0.19-bp153.2.8.1</FullProductName>
    </Branch>
    <Relationship ProductReference="gdcm-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:gdcm-3.0.19-bp153.2.8.1">gdcm-3.0.19-bp153.2.8.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-applications-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:gdcm-applications-3.0.19-bp153.2.8.1">gdcm-applications-3.0.19-bp153.2.8.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-devel-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:gdcm-devel-3.0.19-bp153.2.8.1">gdcm-devel-3.0.19-bp153.2.8.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-examples-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:gdcm-examples-3.0.19-bp153.2.8.1">gdcm-examples-3.0.19-bp153.2.8.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdcm3_0-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:libgdcm3_0-3.0.19-bp153.2.8.1">libgdcm3_0-3.0.19-bp153.2.8.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libsocketxx1_2-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:libsocketxx1_2-3.0.19-bp153.2.8.1">libsocketxx1_2-3.0.19-bp153.2.8.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-1.11.2-bp153.2.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:orthanc-1.11.2-bp153.2.13.1">orthanc-1.11.2-bp153.2.13.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-devel-1.11.2-bp153.2.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:orthanc-devel-1.11.2-bp153.2.13.1">orthanc-devel-1.11.2-bp153.2.13.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-doc-1.11.2-bp153.2.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:orthanc-doc-1.11.2-bp153.2.13.1">orthanc-doc-1.11.2-bp153.2.13.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-gdcm-1.5-bp153.2.6.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:orthanc-gdcm-1.5-bp153.2.6.1">orthanc-gdcm-1.5-bp153.2.6.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-source-1.11.2-bp153.2.13.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:orthanc-source-1.11.2-bp153.2.13.1">orthanc-source-1.11.2-bp153.2.13.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-webviewer-2.8-bp153.2.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:orthanc-webviewer-2.8-bp153.2.3.1">orthanc-webviewer-2.8-bp153.2.3.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-gdcm-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:python3-gdcm-3.0.19-bp153.2.8.1">python3-gdcm-3.0.19-bp153.2.8.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:gdcm-3.0.19-bp153.2.8.1">gdcm-3.0.19-bp153.2.8.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-applications-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:gdcm-applications-3.0.19-bp153.2.8.1">gdcm-applications-3.0.19-bp153.2.8.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-devel-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:gdcm-devel-3.0.19-bp153.2.8.1">gdcm-devel-3.0.19-bp153.2.8.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-examples-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:gdcm-examples-3.0.19-bp153.2.8.1">gdcm-examples-3.0.19-bp153.2.8.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdcm3_0-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libgdcm3_0-3.0.19-bp153.2.8.1">libgdcm3_0-3.0.19-bp153.2.8.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libsocketxx1_2-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libsocketxx1_2-3.0.19-bp153.2.8.1">libsocketxx1_2-3.0.19-bp153.2.8.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-1.11.2-bp153.2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:orthanc-1.11.2-bp153.2.13.1">orthanc-1.11.2-bp153.2.13.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-devel-1.11.2-bp153.2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:orthanc-devel-1.11.2-bp153.2.13.1">orthanc-devel-1.11.2-bp153.2.13.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-doc-1.11.2-bp153.2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:orthanc-doc-1.11.2-bp153.2.13.1">orthanc-doc-1.11.2-bp153.2.13.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-gdcm-1.5-bp153.2.6.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:orthanc-gdcm-1.5-bp153.2.6.1">orthanc-gdcm-1.5-bp153.2.6.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-source-1.11.2-bp153.2.13.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:orthanc-source-1.11.2-bp153.2.13.1">orthanc-source-1.11.2-bp153.2.13.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-webviewer-2.8-bp153.2.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:orthanc-webviewer-2.8-bp153.2.3.1">orthanc-webviewer-2.8-bp153.2.3.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-gdcm-3.0.19-bp153.2.8.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:python3-gdcm-3.0.19-bp153.2.8.1">python3-gdcm-3.0.19-bp153.2.8.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.</Note>
    </Notes>
    <CVE>CVE-2022-2119</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP3:gdcm-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:gdcm-applications-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:gdcm-devel-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:gdcm-examples-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:libgdcm3_0-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:libsocketxx1_2-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-devel-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-doc-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-gdcm-1.5-bp153.2.6.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-source-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-webviewer-2.8-bp153.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:python3-gdcm-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gdcm-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gdcm-applications-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gdcm-devel-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gdcm-examples-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libgdcm3_0-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libsocketxx1_2-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-devel-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-doc-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-gdcm-1.5-bp153.2.6.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-source-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-webviewer-2.8-bp153.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python3-gdcm-3.0.19-bp153.2.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K67WDY4JVASQKGAJHGMCE45SJSPPFKPM/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-2119.html</URL>
        <Description>CVE-2022-2119</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208637</URL>
        <Description>SUSE Bug 1208637</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.</Note>
    </Notes>
    <CVE>CVE-2022-2120</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP3:gdcm-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:gdcm-applications-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:gdcm-devel-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:gdcm-examples-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:libgdcm3_0-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:libsocketxx1_2-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-devel-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-doc-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-gdcm-1.5-bp153.2.6.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-source-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:orthanc-webviewer-2.8-bp153.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:python3-gdcm-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gdcm-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gdcm-applications-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gdcm-devel-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gdcm-examples-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libgdcm3_0-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libsocketxx1_2-3.0.19-bp153.2.8.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-devel-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-doc-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-gdcm-1.5-bp153.2.6.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-source-1.11.2-bp153.2.13.1</ProductID>
        <ProductID>openSUSE Leap 15.3:orthanc-webviewer-2.8-bp153.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.3:python3-gdcm-3.0.19-bp153.2.8.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/K67WDY4JVASQKGAJHGMCE45SJSPPFKPM/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-2120.html</URL>
        <Description>CVE-2022-2120</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208638</URL>
        <Description>SUSE Bug 1208638</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
