[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4374-1] pdfminer security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4374-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                           Chris Lamb
November 18, 2025                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : pdfminer
Version        : 20200726-1+deb11u1
CVE ID         : CVE-2025-64512
Debian Bug     : 1120642

It was discovered that there was a potential arbitrary code execution
in pdfminer, a tool for extracting information from PDF documents. A
malicious, zipped pickle file could have contained code that might
have been executed when the PDF was processed.

For Debian 11 bullseye, this problem has been fixed in version
20200726-1+deb11u1.

We recommend that you upgrade your pdfminer packages.

For the detailed security status of pdfminer please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pdfminer

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmkc7yMACgkQHpU+J9Qx
HljDJw/+P3pfPwJwZ/sBiJ+ISAMMGeXyFlaBr90HsPudw1ixrooY/ohDbrGIhpN0
Ra5pYfIqYaDiW5hrzbzisiUiftcjyzFkNUixL+pAThEqAIVDVr2dBBEv4amAmWtt
vfi+u2Pa45C+rxc2MWOuplhA/y8FEqlLFRs5T5zsU9o7nir2KH1uQAke5DZyMz4G
DkxgZGxZf5GQbIwcQb6o3qoqWt3bkKfHqRMF0MJCQX4lImfKcL36m9lYsBHXRXBM
bg37gfe8NTd6l8PWap7YwOmpMtWWuchRr6yGrlMLSBENxfFT8RHedyw+zz72IX+Z
rzVvnEiIfI9nOquWKxgiV9g/DUTEx2zVgBIaRifd9Mw4WDxGawXLVBt+TlhvVF7u
bQQlev61dojqyM/ZRFvZV8UnxB0TP5G6bT8U8hXXKnanRKMhYoyPp1tNXiYGGThS
PV37QQTgnIb/ntReBpIPDW97RLrYfc40GXOzpnOSkWzcI5e0ALP3v0mjW0iBlVtJ
Kk3b9kDeVQE87OYMPrLNxCeEnAqNrsXKlBdxsO4nvkuqI2mrTq1Kbp+cczCkal01
QCa/YlM+JvOT1DzKXkxe8NFXcDYlcvfwaynVkJLKKtb6yv67jBKlKPcWfgIZnP/e
K3qnA/5h2UiSpx7J6Kdj656suA9whUYWs0AgB7cGbpfpoT2JEEI=
=N8zp
-----END PGP SIGNATURE-----


Reply to: