Hello team,
Can somebody publish DLA for calibre_5.12.0+dfsg-1+deb11u4 please. My
security tracker repo is broken* at the moment.
Here is the content for mail announcement.
===
Multiple vulnerabilities have been discovered in calibre, an e-book
manager
CVE-2025-64486
calibre does not validate filenames when handling binary assets in
FB2 files, allowing an attacker to write arbitrary files on the
filesystem when viewing or converting a malicious FictionBook
file. This can be leveraged to achieve arbitrary code execution.
CVE-2026-25635
Calibre's CHM reader contains a path traversal vulnerability that
allows arbitrary file writes anywhere the user has write
permissions.
CVE-2026-25636
a path traversal vulnerability in Calibre's EPUB conversion allows
a malicious EPUB file to corrupt arbitrary existing files writable
by the Calibre process
CVE-2026-26064
a path traversal vulnerability that allows arbitrary file writes
anywhere the user has write permissions.
CVE-2026-26065
Path Traversal through PDB readers that allow arbitrary file
writes with arbitrary extension and arbitrary content anywhere the
user has write permissions. Files are written in 'wb' mode,
silently overwriting existing files. This can lead to potential
code execution and Denial of Service through file corruption.
=====
* - My desktop copy of security-tracker have not updated since some
time and when I do pull, I am getting timeouts and similar errors,
which have reported in #debian-salsa.
Thanks in advance
Abhijith PA
Attachment:
signature.asc
Description: PGP signature