-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 13 Nov 2025 22:53:52 +0100 Source: pdfminer Architecture: source Version: 20221105+dfsg-1.1 Distribution: unstable Urgency: medium Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Salvatore Bonaccorso <carnil@debian.org> Closes: 1120642 Changes: pdfminer (20221105+dfsg-1.1) unstable; urgency=medium . * Non-maintainer upload. * Fix: arbitary code execution when loading pickle font files (CVE-2025-64512) (Closes: #1120642) Checksums-Sha1: 35a783efe879269bd4bafe582c7980e2bf18cdbc 2508 pdfminer_20221105+dfsg-1.1.dsc ba3609cf8086e9ffc81be43742cd7e3862d33ccc 12724 pdfminer_20221105+dfsg-1.1.debian.tar.xz 740b552a4bbf1255622838e4daa932a8238e5107 7239 pdfminer_20221105+dfsg-1.1_source.buildinfo Checksums-Sha256: 5f1cb5fe5fe43700552c7f0d8b84a34bef8ed3097d1d7658260799eb3db28c08 2508 pdfminer_20221105+dfsg-1.1.dsc f7a40c2cdedfe4dc6d2337aec802f2cdf0d6cb50cb1837d4e6ae4184a9b95c38 12724 pdfminer_20221105+dfsg-1.1.debian.tar.xz b3a6f659e9cfd03eb5df54c68f4c32cfd85c01c2202ba6f6d759a513ae2512dd 7239 pdfminer_20221105+dfsg-1.1_source.buildinfo Files: cd2dfe98939c60dc8bd768e4c18ea2a3 2508 python optional pdfminer_20221105+dfsg-1.1.dsc fafa134c6435fefd87bdf5608925f3d5 12724 python optional pdfminer_20221105+dfsg-1.1.debian.tar.xz 30ec5475fd564faba450b534e014559b 7239 python optional pdfminer_20221105+dfsg-1.1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmkWVhlfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk ZWJpYW4ub3JnAAoJEAVMuPMTQ89EHpcP/2pCHn3tv5GFAjC0yEEVZqkC40+dOwdK U/9IR0Vqd7bIwStw4ZcmE6Pb5o3ORzfbiaymALYHSxqixlcAdGdc8jxImXZ6n3TI K4jGeZjKblQ5neK9RK3VJgqeMP2qRY8hPAuR+uLYWpqG5aFAXOV4VFRSzGqtWAtz w+NhLXbhXyIUaHeyQVnU5qXahbWAPoqKMtYu4t0qdU0wPpC+gfnV/TgVWgHXUuey BQmMEfEZxIs23UhXrhUsfrSDwPjGHvcYEsRMDMTuFeF2M3yolicrMFX3bAb3dZEa rqDfWS9uZEATEDQ03j4JInMqvh+TpA6HHOSSNgGw/vZ/pn4ienJLbg6xWTPTyTiB NyJdeHlD+hSifTMTz3QWKzwimhM9SVqd90HG5HDe09gtteFSgtPjzHLZCtu1hN/9 Q+kgPxR1mElJ4kBuX+HMVseHkuLo+wJ7oT72QA194uxpIdGQOx2q7l9tvDirN1it 7iT7Cf/o2YMY8BswbEnn18WCV/vxf6IB4StfLz8dciXBuejXHLeqwI64ZTz2uMZP 9WMEXllU0NVhrNDMcXYJ/llfjjkMQxNa7FPJQqmyv9GLSsjy++fE2dNG2me8R7pr 049Cz5PhOP+wLO3roEPXSGJVgd7BHYzynwgGKApRtNmiseOEONF+xhmRUmpD5KtU hwzG2cfd+a4P =i+vN -----END PGP SIGNATURE-----