<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for gdcm, orthanc, orthanc-gdcm, orthanc-webviewer</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2022:10145-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2022-10-12T15:35:24Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2022-10-12T15:35:24Z</InitialReleaseDate>
    <CurrentReleaseDate>2022-10-12T15:35:24Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for gdcm, orthanc, orthanc-gdcm, orthanc-webviewer</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for gdcm, orthanc, orthanc-gdcm, orthanc-webviewer fixes the following issues:

Changes in gdcm:

- rename of gdcm-libgdcm3_0 to libgdcm3_0 (proposal S. Brüns)

- version 3.0.18

  no changelog

- version 3.0.12

  * support for poppler 22.03 added

Changes in orthanc-gdcm:

- changed dependency gdcm-libgdcm3_0 -&gt; libgdcm3_0

Changes in orthanc:

- version 1.11.2
  * Added support for RGBA64 images in tools/create-dicom and /preview
  * New configuration 'MaximumStorageMode' to choose between recyling of
    old patients (default behavior) and rejection of new incoming data when
    the MaximumStorageSize has been reached.
  * New sample plugin: 'DelayedDeletion' that will delete files from disk
    asynchronously to speed up deletion of large studies.
  * Lua: new 'SetHttpTimeout' function
  * Lua: new 'OnHeartBeat' callback called at regular interval provided that
       you have configured 'LuaHeartBeatPeriod' &gt; 0.
  * 'ExtraMainDicomTags' configuration now accepts Dicom Sequences.  Sequences are
    stored in a dedicated new metadata 'MainDicomSequences'.  This should improve
    DicomWeb QIDO-RS and avoid warnings like 'Accessing Dicom tags from storage when 
    accessing series : 0040,0275'.
    Main dicom sequences can now be returned in 'MainDicomTags' and in 'RequestedTags'.
  * Fix the 'Never' option of the 'StorageAccessOnFind' that was sill accessing
    files (bug introduced in 1.11.0).
  * Fix the Storage Cache for compressed files (bug introduced in 1.11.1).
  * Fix the storage cache that was not used by the Plugin SDK.  This fixes the 
    DicomWeb plugin '/rendered' route performance issues.
  * DelayedDeletion plugin: Fix leaking of symbols
  * SQLite now closes and deletes WAL and SHM files on exit.  This should improve
    handling of SQLite DB over network drives.
  * Fix static compilation of boost 1.69 on Ubuntu 22.04
  * Upgraded dependencies for static builds:
    - boost 1.80.0
    - dcmtk 3.6.7  (fixes CVE-2022-2119 and CVE-2022-2120)
    - openssl 3.0.5
  * Housekeeper plugin: Fix resume of previous processing
  * Added missing MOVEPatientRootQueryRetrieveInformationModel in 
    DicomControlUserConnection::SetupPresentationContexts()
  * Improved HttpClient error logging (add method + url)
  * API version upgraded to 18
  * /system is now reporting 'DatabaseServerIdentifier'
  * Added an Asynchronous mode to /modalities/../move.
  * 'RequestedTags' option can now include DICOM sequences.
  * New function in the SDK: 'OrthancPluginGetDatabaseServerIdentifier'
  * DicomMap::ParseMainDicomTags has been deprecated -&gt; retrieve 'full' tags
    and use DicomMap::FromDicomAsJson instead

Changes in orthanc-webviewer:

- version 2.8

  * Fix XSS inside DICOM in Orthanc Web Viewer (as reported by Stuart
    Kurutac, NCC Group)
  * framework190.diff removed (covered in actual version)  
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2022-10145</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OTK3TBM5PVZQBCMNB7R6KN74EKSALYHH/</URL>
      <Description>E-Mail link for openSUSE-SU-2022:10145-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-2119/</URL>
      <Description>SUSE CVE CVE-2022-2119 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-2120/</URL>
      <Description>SUSE CVE CVE-2022-2120 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Package Hub 15 SP4">
      <Branch Type="Product Name" Name="SUSE Package Hub 15 SP4">
        <FullProductName ProductID="SUSE Package Hub 15 SP4">SUSE Package Hub 15 SP4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.4">
      <Branch Type="Product Name" Name="openSUSE Leap 15.4">
        <FullProductName ProductID="openSUSE Leap 15.4" CPE="cpe:/o:opensuse:leap:15.4">openSUSE Leap 15.4</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="gdcm-3.0.19-bp154.2.5.1">
      <FullProductName ProductID="gdcm-3.0.19-bp154.2.5.1">gdcm-3.0.19-bp154.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gdcm-applications-3.0.19-bp154.2.5.1">
      <FullProductName ProductID="gdcm-applications-3.0.19-bp154.2.5.1">gdcm-applications-3.0.19-bp154.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gdcm-devel-3.0.19-bp154.2.5.1">
      <FullProductName ProductID="gdcm-devel-3.0.19-bp154.2.5.1">gdcm-devel-3.0.19-bp154.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gdcm-examples-3.0.19-bp154.2.5.1">
      <FullProductName ProductID="gdcm-examples-3.0.19-bp154.2.5.1">gdcm-examples-3.0.19-bp154.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libgdcm3_0-3.0.19-bp154.2.5.1">
      <FullProductName ProductID="libgdcm3_0-3.0.19-bp154.2.5.1">libgdcm3_0-3.0.19-bp154.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libsocketxx1_2-3.0.19-bp154.2.5.1">
      <FullProductName ProductID="libsocketxx1_2-3.0.19-bp154.2.5.1">libsocketxx1_2-3.0.19-bp154.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-1.11.2-bp154.2.3.1">
      <FullProductName ProductID="orthanc-1.11.2-bp154.2.3.1">orthanc-1.11.2-bp154.2.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-devel-1.11.2-bp154.2.3.1">
      <FullProductName ProductID="orthanc-devel-1.11.2-bp154.2.3.1">orthanc-devel-1.11.2-bp154.2.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-doc-1.11.2-bp154.2.3.1">
      <FullProductName ProductID="orthanc-doc-1.11.2-bp154.2.3.1">orthanc-doc-1.11.2-bp154.2.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-gdcm-1.5-bp154.2.3.1">
      <FullProductName ProductID="orthanc-gdcm-1.5-bp154.2.3.1">orthanc-gdcm-1.5-bp154.2.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-source-1.11.2-bp154.2.3.1">
      <FullProductName ProductID="orthanc-source-1.11.2-bp154.2.3.1">orthanc-source-1.11.2-bp154.2.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="orthanc-webviewer-2.8-bp154.2.3.1">
      <FullProductName ProductID="orthanc-webviewer-2.8-bp154.2.3.1">orthanc-webviewer-2.8-bp154.2.3.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python3-gdcm-3.0.19-bp154.2.5.1">
      <FullProductName ProductID="python3-gdcm-3.0.19-bp154.2.5.1">python3-gdcm-3.0.19-bp154.2.5.1</FullProductName>
    </Branch>
    <Relationship ProductReference="gdcm-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:gdcm-3.0.19-bp154.2.5.1">gdcm-3.0.19-bp154.2.5.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-applications-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:gdcm-applications-3.0.19-bp154.2.5.1">gdcm-applications-3.0.19-bp154.2.5.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-devel-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:gdcm-devel-3.0.19-bp154.2.5.1">gdcm-devel-3.0.19-bp154.2.5.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-examples-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:gdcm-examples-3.0.19-bp154.2.5.1">gdcm-examples-3.0.19-bp154.2.5.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdcm3_0-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:libgdcm3_0-3.0.19-bp154.2.5.1">libgdcm3_0-3.0.19-bp154.2.5.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libsocketxx1_2-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:libsocketxx1_2-3.0.19-bp154.2.5.1">libsocketxx1_2-3.0.19-bp154.2.5.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-1.11.2-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:orthanc-1.11.2-bp154.2.3.1">orthanc-1.11.2-bp154.2.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-devel-1.11.2-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:orthanc-devel-1.11.2-bp154.2.3.1">orthanc-devel-1.11.2-bp154.2.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-doc-1.11.2-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:orthanc-doc-1.11.2-bp154.2.3.1">orthanc-doc-1.11.2-bp154.2.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-gdcm-1.5-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:orthanc-gdcm-1.5-bp154.2.3.1">orthanc-gdcm-1.5-bp154.2.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-source-1.11.2-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:orthanc-source-1.11.2-bp154.2.3.1">orthanc-source-1.11.2-bp154.2.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-webviewer-2.8-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:orthanc-webviewer-2.8-bp154.2.3.1">orthanc-webviewer-2.8-bp154.2.3.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-gdcm-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP4">
      <FullProductName ProductID="SUSE Package Hub 15 SP4:python3-gdcm-3.0.19-bp154.2.5.1">python3-gdcm-3.0.19-bp154.2.5.1 as a component of SUSE Package Hub 15 SP4</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:gdcm-3.0.19-bp154.2.5.1">gdcm-3.0.19-bp154.2.5.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-applications-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:gdcm-applications-3.0.19-bp154.2.5.1">gdcm-applications-3.0.19-bp154.2.5.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-devel-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:gdcm-devel-3.0.19-bp154.2.5.1">gdcm-devel-3.0.19-bp154.2.5.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="gdcm-examples-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:gdcm-examples-3.0.19-bp154.2.5.1">gdcm-examples-3.0.19-bp154.2.5.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libgdcm3_0-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:libgdcm3_0-3.0.19-bp154.2.5.1">libgdcm3_0-3.0.19-bp154.2.5.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="libsocketxx1_2-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:libsocketxx1_2-3.0.19-bp154.2.5.1">libsocketxx1_2-3.0.19-bp154.2.5.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-1.11.2-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:orthanc-1.11.2-bp154.2.3.1">orthanc-1.11.2-bp154.2.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-devel-1.11.2-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:orthanc-devel-1.11.2-bp154.2.3.1">orthanc-devel-1.11.2-bp154.2.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-doc-1.11.2-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:orthanc-doc-1.11.2-bp154.2.3.1">orthanc-doc-1.11.2-bp154.2.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-gdcm-1.5-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:orthanc-gdcm-1.5-bp154.2.3.1">orthanc-gdcm-1.5-bp154.2.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-source-1.11.2-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:orthanc-source-1.11.2-bp154.2.3.1">orthanc-source-1.11.2-bp154.2.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="orthanc-webviewer-2.8-bp154.2.3.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:orthanc-webviewer-2.8-bp154.2.3.1">orthanc-webviewer-2.8-bp154.2.3.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
    <Relationship ProductReference="python3-gdcm-3.0.19-bp154.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.4">
      <FullProductName ProductID="openSUSE Leap 15.4:python3-gdcm-3.0.19-bp154.2.5.1">python3-gdcm-3.0.19-bp154.2.5.1 as a component of openSUSE Leap 15.4</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.</Note>
    </Notes>
    <CVE>CVE-2022-2119</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP4:gdcm-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:gdcm-applications-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:gdcm-devel-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:gdcm-examples-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:libgdcm3_0-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:libsocketxx1_2-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-devel-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-doc-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-gdcm-1.5-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-source-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-webviewer-2.8-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:python3-gdcm-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:gdcm-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:gdcm-applications-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:gdcm-devel-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:gdcm-examples-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:libgdcm3_0-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:libsocketxx1_2-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-devel-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-doc-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-gdcm-1.5-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-source-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-webviewer-2.8-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:python3-gdcm-3.0.19-bp154.2.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OTK3TBM5PVZQBCMNB7R6KN74EKSALYHH/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-2119.html</URL>
        <Description>CVE-2022-2119</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208637</URL>
        <Description>SUSE Bug 1208637</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.</Note>
    </Notes>
    <CVE>CVE-2022-2120</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP4:gdcm-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:gdcm-applications-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:gdcm-devel-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:gdcm-examples-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:libgdcm3_0-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:libsocketxx1_2-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-devel-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-doc-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-gdcm-1.5-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-source-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:orthanc-webviewer-2.8-bp154.2.3.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP4:python3-gdcm-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:gdcm-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:gdcm-applications-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:gdcm-devel-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:gdcm-examples-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:libgdcm3_0-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:libsocketxx1_2-3.0.19-bp154.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-devel-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-doc-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-gdcm-1.5-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-source-1.11.2-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:orthanc-webviewer-2.8-bp154.2.3.1</ProductID>
        <ProductID>openSUSE Leap 15.4:python3-gdcm-3.0.19-bp154.2.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/OTK3TBM5PVZQBCMNB7R6KN74EKSALYHH/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-2120.html</URL>
        <Description>CVE-2022-2120</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1208638</URL>
        <Description>SUSE Bug 1208638</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
