[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Please publish DLA for calibre.



Hello team,

Can somebody publish DLA for calibre_5.12.0+dfsg-1+deb11u4 please. My
security tracker repo is broken* at the moment.

Here is the content for mail announcement.

===

Multiple vulnerabilities have been discovered in calibre, an e-book
manager

CVE-2025-64486

    calibre does not validate filenames when handling binary assets in
    FB2 files, allowing an attacker to write arbitrary files on the
    filesystem when viewing or converting a malicious FictionBook
    file. This can be leveraged to achieve arbitrary code execution.

CVE-2026-25635

    Calibre's CHM reader contains a path traversal vulnerability that
    allows arbitrary file writes anywhere the user has write
    permissions.

CVE-2026-25636

    a path traversal vulnerability in Calibre's EPUB conversion allows
    a malicious EPUB file to corrupt arbitrary existing files writable
    by the Calibre process

CVE-2026-26064

    a path traversal vulnerability that allows arbitrary file writes
    anywhere the user has write permissions.

CVE-2026-26065

    Path Traversal through PDB readers that allow arbitrary file
    writes with arbitrary extension and arbitrary content anywhere the
    user has write permissions. Files are written in 'wb' mode,
    silently overwriting existing files. This can lead to potential
    code execution and Denial of Service through file corruption.

=====

* - My desktop copy of security-tracker have not updated since some
    time and when I do pull, I am getting timeouts and similar errors,
    which have reported in #debian-salsa.


Thanks in advance
Abhijith PA

Attachment: signature.asc
Description: PGP signature


Reply to: