Oval Definition:oval:org.opensuse.security:def:441
Revision Date:2022-10-12Version:1
Title:Security update for gdcm, orthanc, orthanc-gdcm, orthanc-webviewer (Important)
Description:

This update for gdcm, orthanc, orthanc-gdcm, orthanc-webviewer fixes the following issues:

Changes in gdcm:

- rename of gdcm-libgdcm3_0 to libgdcm3_0 (proposal S. Br?ns)

- version 3.0.18

no changelog

- version 3.0.12

* support for poppler 22.03 added

Changes in orthanc-gdcm:

- changed dependency gdcm-libgdcm3_0 -> libgdcm3_0

Changes in orthanc:

- version 1.11.2 * Added support for RGBA64 images in tools/create-dicom and /preview * New configuration 'MaximumStorageMode' to choose between recyling of old patients (default behavior) and rejection of new incoming data when the MaximumStorageSize has been reached. * New sample plugin: 'DelayedDeletion' that will delete files from disk asynchronously to speed up deletion of large studies. * Lua: new 'SetHttpTimeout' function * Lua: new 'OnHeartBeat' callback called at regular interval provided that you have configured 'LuaHeartBeatPeriod' > 0. * 'ExtraMainDicomTags' configuration now accepts Dicom Sequences. Sequences are stored in a dedicated new metadata 'MainDicomSequences'. This should improve DicomWeb QIDO-RS and avoid warnings like 'Accessing Dicom tags from storage when accessing series : 0040,0275'. Main dicom sequences can now be returned in 'MainDicomTags' and in 'RequestedTags'. * Fix the 'Never' option of the 'StorageAccessOnFind' that was sill accessing files (bug introduced in 1.11.0). * Fix the Storage Cache for compressed files (bug introduced in 1.11.1). * Fix the storage cache that was not used by the Plugin SDK. This fixes the DicomWeb plugin '/rendered' route performance issues. * DelayedDeletion plugin: Fix leaking of symbols * SQLite now closes and deletes WAL and SHM files on exit. This should improve handling of SQLite DB over network drives. * Fix static compilation of boost 1.69 on Ubuntu 22.04 * Upgraded dependencies for static builds: - boost 1.80.0 - dcmtk 3.6.7 (fixes CVE-2022-2119 and CVE-2022-2120) - openssl 3.0.5 * Housekeeper plugin: Fix resume of previous processing * Added missing MOVEPatientRootQueryRetrieveInformationModel in DicomControlUserConnection::SetupPresentationContexts() * Improved HttpClient error logging (add method + url) * API version upgraded to 18 * /system is now reporting 'DatabaseServerIdentifier' * Added an Asynchronous mode to /modalities/../move. * 'RequestedTags' option can now include DICOM sequences. * New function in the SDK: 'OrthancPluginGetDatabaseServerIdentifier' * DicomMap::ParseMainDicomTags has been deprecated -> retrieve 'full' tags and use DicomMap::FromDicomAsJson instead

Changes in orthanc-webviewer:

- version 2.8

* Fix XSS inside DICOM in Orthanc Web Viewer (as reported by Stuart Kurutac, NCC Group) * framework190.diff removed (covered in actual version)
Family:unixClass:patch
Status:Reference(s):CVE-2013-6370
CVE-2013-6370
CVE-2013-6371
CVE-2013-6371
CVE-2022-2119
CVE-2022-2120
openSUSE-SU-2022:10145-1
Platform(s):openSUSE 12.3 Update
openSUSE 13.1
openSUSE Leap 15.4
SUSE Linux Enterprise Desktop 12 SP1
SUSE Linux Enterprise Desktop 15 SP1
SUSE Linux Enterprise High Availability 12
SUSE Linux Enterprise High Availability 12 SP1
SUSE Linux Enterprise High Performance Computing 15 SP1
SUSE Linux Enterprise Live Patching 12
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Module for Containers 15
SUSE Linux Enterprise Module for Containers 15 SP1
SUSE Linux Enterprise Module for Development Tools 15
SUSE Linux Enterprise Module for Legacy Software 12
SUSE Linux Enterprise Module for Public Cloud 12
SUSE Linux Enterprise Server 15 SP1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Storage 6
SUSE Manager Proxy 4.0
SUSE Manager Server 4.0
Product(s):
Definition Synopsis
  • openSUSE Leap 15.4 is installed
  • AND Package Information
  • gdcm-3.0.19-bp154.2.5.1 is installed
  • OR gdcm-applications-3.0.19-bp154.2.5.1 is installed
  • OR gdcm-devel-3.0.19-bp154.2.5.1 is installed
  • OR gdcm-examples-3.0.19-bp154.2.5.1 is installed
  • OR libgdcm3_0-3.0.19-bp154.2.5.1 is installed
  • OR libsocketxx1_2-3.0.19-bp154.2.5.1 is installed
  • OR orthanc-1.11.2-bp154.2.3.1 is installed
  • OR orthanc-devel-1.11.2-bp154.2.3.1 is installed
  • OR orthanc-doc-1.11.2-bp154.2.3.1 is installed
  • OR orthanc-gdcm-1.5-bp154.2.3.1 is installed
  • OR orthanc-source-1.11.2-bp154.2.3.1 is installed
  • OR orthanc-webviewer-2.8-bp154.2.3.1 is installed
  • OR python3-gdcm-3.0.19-bp154.2.5.1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Desktop 12 SP1 is installed
  • AND Package Information
  • pam_ssh-2.0-1 is installed
  • OR pam_ssh-32bit-2.0-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • libjson-c-devel-0.13-1.19 is installed
  • OR libjson-c3-0.13-1.19 is installed
  • OR libjson-c3-32bit-0.13-1.19 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • libjson-c-devel-0.13-1 is installed
  • OR libjson-c3-0.13-1 is installed
  • OR libjson-c3-32bit-0.13-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Containers 15 is installed
  • AND Package Information
  • containerd-1.1.2-5.3 is installed
  • OR docker-18.06.1_ce-6.8 is installed
  • OR docker-bash-completion-18.06.1_ce-6.8 is installed
  • OR docker-libnetwork-0.7.0.1+gitr2664_3ac297bc7fd0-4.3 is installed
  • OR docker-runc-1.0.0rc5+gitr3562_69663f0bd4b6-6.3 is installed
  • OR golang-github-docker-libnetwork-0.7.0.1+gitr2664_3ac297bc7fd0-4.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Containers 15 SP1 is installed
  • AND Package Information
  • docker-18.09.6_ce-6.20 is installed
  • OR docker-bash-completion-18.09.6_ce-6.20 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Development Tools 15 is installed
  • AND python3-tools-3.6.5-1 is installed
  • BACK