An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.
Orthanc recommends users update to v1.13.0.
https://orthanc.uclouvain.be/downloads/index.html