Debian Package Tracker
Register | Log in
Subscribe

pdfminer

Choose email to subscribe with

general
  • source: pdfminer (main)
  • version: 20260107+dfsg-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Daniel Kahn Gillmor [DMD] – Daniele Tricoli [DMD]
  • arch: all
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 20200726-1
  • o-o-sec: 20200726-1+deb11u2
  • oldstable: 20221105+dfsg-1.1~deb12u1
  • old-sec: 20221105+dfsg-1.1~deb12u1
  • stable: 20221105+dfsg-1.1~deb13u1
  • stable-sec: 20221105+dfsg-1.1~deb13u1
  • testing: 20260107+dfsg-1
  • unstable: 20260107+dfsg-1
versioned links
  • 20200726-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20200726-1+deb11u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20221105+dfsg-1.1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20221105+dfsg-1.1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 20260107+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • pdfminer-data (1 bugs: 0, 1, 0, 0)
  • python3-pdfminer
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-70559: pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.
Created: 2026-02-03 Last update: 2026-02-04 06:00
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2025-70559: pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.
Created: 2026-02-03 Last update: 2026-02-04 06:00
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2025-01-06 Last update: 2026-02-09 19:30
Depends on packages which need a new maintainer normal
The packages that pdfminer depends on which need a new maintainer are:
  • docbook-xml (#802368)
    • Build-Depends: docbook-xml
  • docbook-xsl (#802370)
    • Build-Depends: docbook-xsl
Created: 2023-09-01 Last update: 2026-02-09 19:00
debian/patches: 1 patch to forward upstream low

Among the 1 debian patch available in version 20260107+dfsg-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2026-01-18 13:31
news
[rss feed]
  • [2026-01-20] pdfminer 20260107+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-18] Accepted pdfminer 20260107+dfsg-1 (source) into unstable (Boyuan Yang)
  • [2026-01-08] Accepted pdfminer 20200726-1+deb11u2 (source) into oldoldstable-security (Chris Lamb)
  • [2025-11-29] Accepted pdfminer 20221105+dfsg-1.1~deb12u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-11-29] Accepted pdfminer 20221105+dfsg-1.1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-11-25] Accepted pdfminer 20221105+dfsg-1.1~deb12u1 (source) into oldstable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-11-25] Accepted pdfminer 20221105+dfsg-1.1~deb13u1 (source) into stable-security (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2025-11-18] Accepted pdfminer 20200726-1+deb11u1 (source) into oldoldstable-security (Chris Lamb)
  • [2025-11-18] pdfminer 20221105+dfsg-1.1 MIGRATED to testing (Debian testing watch)
  • [2025-11-15] Accepted pdfminer 20221105+dfsg-1.1 (source) into unstable (Salvatore Bonaccorso)
  • [2023-01-16] pdfminer 20221105+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2023-01-16] pdfminer 20221105+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-19] Accepted pdfminer 20221105+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2022-03-25] pdfminer 20220319+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2022-03-22] Accepted pdfminer 20220319+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2021-08-28] pdfminer 20201018+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-08-25] Accepted pdfminer 20201018+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2020-08-12] pdfminer 20200726-1 MIGRATED to testing (Debian testing watch)
  • [2020-08-09] Accepted pdfminer 20200726-1 (source) into unstable (Emmanuel Arias) (signed by: Jonathan Carter)
  • [2020-07-12] pdfminer 20191020+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2020-07-09] Accepted pdfminer 20191020+dfsg-3 (source) into unstable (Daniele Tricoli)
  • [2019-12-23] pdfminer 20191020+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2019-12-21] Accepted pdfminer 20191020+dfsg-2 (source) into unstable (Daniele Tricoli)
  • [2019-12-15] pdfminer 20191020+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2019-12-09] Accepted pdfminer 20191020+dfsg-1 (source) into unstable (Daniele Tricoli)
  • [2019-01-15] pdfminer 20181108+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2019-01-12] Accepted pdfminer 20181108+dfsg-3 (source all) into unstable (Daniele Tricoli)
  • [2019-01-10] pdfminer 20181108+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2019-01-08] Accepted pdfminer 20181108+dfsg-2 (source all) into unstable (Daniele Tricoli)
  • [2019-01-06] Accepted pdfminer 20181108+dfsg-1 (source all) into unstable (Daniele Tricoli)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 1
  • M&W: 0
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 20260107+dfsg-1
  • 4 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing