-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 18 Nov 2025 11:19:23 -0800 Source: pdfminer Architecture: source Version: 20200726-1+deb11u1 Distribution: bullseye-security Urgency: high Maintainer: Debian Python Modules Team <python-modules-team@lists.alioth.debian.org> Changed-By: Chris Lamb <lamby@debian.org> Closes: 1120642 Changes: pdfminer (20200726-1+deb11u1) bullseye-security; urgency=high . * Non-maintainer upload by the Debian LTS team. * CVE-2025-64512: Fix an arbitrary code execution issue. A malicious, zipped pickle file could have contained code that would automatically have execute when the PDF was processed. (Closes: #1120642) Checksums-Sha1: 5586d27426b541af1e7c7656dd21ccbb0cf831a5 2370 pdfminer_20200726-1+deb11u1.dsc 137ac25168d3a25cb437b5004d089bd4eea2e0d2 5132764 pdfminer_20200726.orig.tar.xz 827d58105467fe1de1b150a9520f0ff04fe3caf6 11968 pdfminer_20200726-1+deb11u1.debian.tar.xz 527df97955a739ef8e57f2501405a11ef6f7b60a 5350 pdfminer_20200726-1+deb11u1_source.buildinfo Checksums-Sha256: a6ca01df094265e0725d9bf7501c128d6a529685ef86b87c068cf654997bc0f7 2370 pdfminer_20200726-1+deb11u1.dsc 970e7b06215c9a9d770af1dba9378f7ffffee7dd386e2926d0eee07a4114a6f1 5132764 pdfminer_20200726.orig.tar.xz 699cdc6f753e993325c9f3f90ade5f7bef3d56381ae95b66fac59d35205eed6e 11968 pdfminer_20200726-1+deb11u1.debian.tar.xz 2dd28b2c418ae76500af385c11fe57460ed9f76f45570e52ee95ba3d1eee218d 5350 pdfminer_20200726-1+deb11u1_source.buildinfo Files: aa2c2b89fd05bb689fa0a6c0ae12a421 2370 python optional pdfminer_20200726-1+deb11u1.dsc cbab64f3d5331676a955dc24f51a0355 5132764 python optional pdfminer_20200726.orig.tar.xz 2cb51443b3baaa44b7bd2ade9ead17b6 11968 python optional pdfminer_20200726-1+deb11u1.debian.tar.xz d4bc165469aa2a7576e0a388428c82f4 5350 python optional pdfminer_20200726-1+deb11u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmkc70YACgkQHpU+J9Qx HlgYhA/+M+iCN977HyJd4XlGL5oGwXAzx88T18GPj/INVXaLUzyMNr442GTEOH/X PBfcJsis/TCFP4fc+MBlYuLRVaCvLOiUPp47KBgCCDGOA4x5IL2SbvcIG92JKC3h 02c0Y2KM17180RMXA31ilBIn96/XTetbZnIY9mefGrF91Aw58FVNgKJQQwfvAueB tAX8vAqYuoNc5vyvW/l4i9g87QshS/iExogzzpC50TYpHKYM5vHEce9W+RNUhLPZ I0xNgACYwiyiROsznZyjArqhcSxvWK4E6hHkaYw4ZlAcMfA0Ppbo7BCRQeXC1vQA 4fLQpmqNaiEkFOTyNuuOzkBD3S4QXazdxw8Qllxt5L/gdMT+kbdhMz2OvAQ+7tOZ GMZHQvaszYrp07b+3p2NHafmAe/brz8mpZUua0SHpuScN38TcQoJnFy4mZXl6FZT XxMxStUpS2Xz6Vv/kiF40al9GwAYXMwCWMbRvibfkZNnkDqoL4EBmxuGnkayLQFs 93I5pos7ayZNQnsHj/vHVMBvlYyYbsOgA4r0RMdQuUI3BNSiyU/6PuJBLC7YQL6R VtU4/vqv5/GivEaQdaYV5D78CwiwJjv9R134WSW7yru4W8+dXVGB2T4V26rXtt41 NwAguWvDsIgvj92YIMQEM15gKkVAkCeHQdFk0fFvmu7QhFQUhB8= =imeu -----END PGP SIGNATURE-----