Information on source package orthanc

Available versions

ReleaseVersion
bullseye1.9.2+really1.9.1+dfsg-1+deb11u1
bullseye (security)1.9.2+really1.9.1+dfsg-1+deb11u2
bookworm1.10.1+dfsg-2+deb12u1
trixie1.12.7+dfsg-4
forky1.12.10+dfsg-2
sid1.12.10+dfsg-2

Open issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-5445vulnerablevulnerablevulnerablevulnerablevulnerableAn out-of-bounds read vulnerability exists in the `DecodeLookupTable` ...
CVE-2026-5444vulnerablevulnerablevulnerablevulnerablevulnerableA heap buffer overflow vulnerability exists in the PAM image parsing l ...
CVE-2026-5443vulnerablevulnerablevulnerablevulnerablevulnerableA heap buffer overflow vulnerability exists during the decoding of `PA ...
CVE-2026-5442vulnerablevulnerablevulnerablevulnerablevulnerableA heap buffer overflow vulnerability exists in the DICOM image decoder ...
CVE-2026-5441vulnerablevulnerablevulnerablevulnerablevulnerableAn out-of-bounds read vulnerability exists in the `DecodePsmctRle1` fu ...
CVE-2026-5440vulnerablevulnerablevulnerablevulnerablevulnerableA memory exhaustion vulnerability exists in the HTTP server due to unb ...
CVE-2026-5439vulnerablevulnerablevulnerablevulnerablevulnerableA memory exhaustion vulnerability exists in ZIP archive processing. Or ...
CVE-2026-5438vulnerablevulnerablevulnerablevulnerablevulnerableA gzip decompression bomb vulnerability exists when Orthanc processes ...
CVE-2026-5437vulnerablevulnerablevulnerablevulnerablevulnerableAn out-of-bounds read vulnerability exists in `DicomStreamReader` duri ...
CVE-2025-15581fixedvulnerablevulnerablefixedfixedOrthanc versions before 1.12.10 are affected by an authorisation logic ...
CVE-2024-22725vulnerable (no DSA)vulnerable (no DSA)fixedfixedfixedOrthanc versions before 1.12.2 are affected by a reflected cross-site ...

Resolved issues

BugDescription
CVE-2025-0896Orthanc server prior to version 1.5.8 does not enable basic authentica ...
CVE-2023-33466Orthanc before 1.12.0 allows authenticated users with access to the Or ...

Security announcements

DSA / DLADescription
DLA-4494-1orthanc - security update
DLA-3562-1orthanc - security update
DSA-5473-1orthanc - security update

Search for package or bug name: Reporting problems