Debian Package Tracker
Register | Log in
Subscribe

psd-tools

Choose email to subscribe with

general
  • source: psd-tools (main)
  • version: 1.17.4+dfsg.1-1
  • maintainer: Ying-Chun Liu (PaulLiu) (DMD)
  • arch: all any
  • std-ver: 4.6.1
  • VCS: unknown
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 1.9.24+dfsg.1-1
  • stable: 1.10.7+dfsg.1-1+deb13u1
  • testing: 1.17.4+dfsg.1-1
  • unstable: 1.17.4+dfsg.1-1
versioned links
  • 1.9.24+dfsg.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.10.7+dfsg.1-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.17.4+dfsg.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-psd-tools
  • python3-psd-tools-doc
action needed
Marked for autoremoval on 12 October due to llvm-toolchain-19, spirv-llvm-translator-19: #1084954, #1095866, #1124069, #1124098, #1133251, #1142869, #1145338 high
Version 1.17.4+dfsg.1-1 of psd-tools is marked for autoremoval from testing on Mon 12 Oct 2026. It depends (transitively) on llvm-toolchain-19, spirv-llvm-translator-19, affected by #1084954, #1095866, #1124069, #1124098, #1133251, #1142869, #1145338. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-08-01 Last update: 2026-09-15 20:33
A new upstream version is available: 1.19.0 high
A new upstream version 1.19.0 is available, you should consider packaging it.
Created: 2026-08-08 Last update: 2026-09-15 17:00
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-49836: psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled and unsanitised, a tool that extracts embedded objects from an untrusted `.psd` can be made to write attacker-chosen bytes to an attacker-chosen path (absolute or `../`-traversing), outside its intended output directory. A secondary issue in `SmartObject.open()` for external-kind smart objects allows the attacker-controlled `fullPath` descriptor to be used as an arbitrary file read path, enabling exfiltration of the read content to the controlled write destination. Both issues are fixed in v1.17.1.
1 issue postponed or untriaged:
  • CVE-2026-27809: (needs triaging) psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() raises ValueError which propagated all the way to the user, crashing psd.composite() and psd-tools export. decompress() already had a fallback that replaces failed channels with black pixels when result is None, but it never triggered because the ValueError from decode_rle() was not caught. The fix in version 1.12.2 wraps the decode_rle() call in a try/except so the existing fallback handles the error gracefully.
Created: 2026-09-11 Last update: 2026-09-11 23:31
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-08-20 Last update: 2026-09-15 17:01
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • python3-psd-tools-doc could be marked Multi-Arch: foreign
Created: 2022-11-11 Last update: 2026-09-15 15:30
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-49836: (needs triaging) psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled and unsanitised, a tool that extracts embedded objects from an untrusted `.psd` can be made to write attacker-chosen bytes to an attacker-chosen path (absolute or `../`-traversing), outside its intended output directory. A secondary issue in `SmartObject.open()` for external-kind smart objects allows the attacker-controlled `fullPath` descriptor to be used as an arbitrary file read path, enabling exfiltration of the read content to the controlled write destination. Both issues are fixed in v1.17.1.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-09-11 Last update: 2026-09-11 23:31
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.1).
Created: 2022-12-17 Last update: 2026-06-25 22:30
news
[rss feed]
  • [2026-07-04] Accepted psd-tools 1.10.7+dfsg.1-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Adrian Bunk)
  • [2026-07-03] psd-tools 1.17.4+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-25] Accepted psd-tools 1.17.4+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-05-23] psd-tools 1.17.0+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-15] Accepted psd-tools 1.17.0+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-05-09] psd-tools 1.16.0+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-30] Accepted psd-tools 1.16.0+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-04-29] psd-tools 1.15.0+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-21] Accepted psd-tools 1.15.0+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-04-21] psd-tools 1.14.3+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-13] Accepted psd-tools 1.14.3+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-04-12] psd-tools 1.14.2+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-04] Accepted psd-tools 1.14.2+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-01-02] psd-tools 1.12.1+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-25] Accepted psd-tools 1.12.1+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2025-12-08] psd-tools 1.12.0+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-30] Accepted psd-tools 1.12.0+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2025-08-21] psd-tools 1.10.9+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-13] Accepted psd-tools 1.10.9+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2025-04-24] psd-tools 1.10.7+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-14] Accepted psd-tools 1.10.7+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2024-09-03] psd-tools 1.9.34+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-26] Accepted psd-tools 1.9.34+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2024-05-17] psd-tools 1.9.32+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-07] Accepted psd-tools 1.9.32+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2024-04-24] psd-tools 1.9.31+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-16] Accepted psd-tools 1.9.31+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2024-01-17] psd-tools 1.9.30+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-09] Accepted psd-tools 1.9.30+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2023-07-11] psd-tools 1.9.28+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 1
  • I&N: 0
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.17.4+dfsg.1-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing