Debian Package Tracker
Register | Log in
Subscribe

psd-tools

Choose email to subscribe with

general
  • source: psd-tools (main)
  • version: 1.17.4+dfsg.1-1
  • maintainer: Ying-Chun Liu (PaulLiu) (DMD)
  • arch: all any
  • std-ver: 4.6.1
  • VCS: unknown
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 1.9.24+dfsg.1-1
  • stable: 1.10.7+dfsg.1-1+deb13u1
  • testing: 1.17.4+dfsg.1-1
  • unstable: 1.17.4+dfsg.1-1
versioned links
  • 1.9.24+dfsg.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.10.7+dfsg.1-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.17.4+dfsg.1-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-psd-tools
  • python3-psd-tools-doc
action needed
Marked for autoremoval on 29 October due to sphinxcontrib-log-cabinet: #1147883, #1147863 high
Version 1.17.4+dfsg.1-1 of psd-tools is marked for autoremoval from testing on Thu 29 Oct 2026. It is affected by #1147883. It depends (transitively) on sphinxcontrib-log-cabinet, affected by #1147863. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-09-22 Last update: 2026-09-25 05:02
A new upstream version is available: 1.19.0 high
A new upstream version 1.19.0 is available, you should consider packaging it.
Created: 2026-08-08 Last update: 2026-09-25 02:04
2 security issues in trixie high

There are 2 open security issues in trixie.

1 important issue:
  • CVE-2026-59991: psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels, depth, and per-layer rectangles, before validating those values against the available file data. A tiny crafted PSD could therefore cause multi-gigabyte memory allocation, and PSDImage.composite() could return a black image with only a warning instead of raising an exception. Services that composite untrusted PSD files could be terminated by out-of-memory handling. This issue is fixed in version 1.17.4.
1 issue left for the package maintainer to handle:
  • CVE-2026-49836: (needs triaging) psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled and unsanitised, a tool that extracts embedded objects from an untrusted `.psd` can be made to write attacker-chosen bytes to an attacker-chosen path (absolute or `../`-traversing), outside its intended output directory. A secondary issue in `SmartObject.open()` for external-kind smart objects allows the attacker-controlled `fullPath` descriptor to be used as an arbitrary file read path, enabling exfiltration of the read content to the controlled write destination. Both issues are fixed in v1.17.1.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-09-11 Last update: 2026-09-24 01:00
3 security issues in bookworm high

There are 3 open security issues in bookworm.

1 important issue:
  • CVE-2026-59991: psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels, depth, and per-layer rectangles, before validating those values against the available file data. A tiny crafted PSD could therefore cause multi-gigabyte memory allocation, and PSDImage.composite() could return a black image with only a warning instead of raising an exception. Services that composite untrusted PSD files could be terminated by out-of-memory handling. This issue is fixed in version 1.17.4.
2 issues postponed or untriaged:
  • CVE-2026-27809: (needs triaging) psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file contains malformed RLE-compressed image data (e.g. a literal run that extends past the expected row size), decode_rle() raises ValueError which propagated all the way to the user, crashing psd.composite() and psd-tools export. decompress() already had a fallback that replaces failed channels with black pixels when result is None, but it never triggered because the ValueError from decode_rle() was not caught. The fix in version 1.12.2 wraps the decode_rle() call in a try/except so the existing fallback handles the error gracefully.
  • CVE-2026-49836: (postponed; to be fixed through a stable update) psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled and unsanitised, a tool that extracts embedded objects from an untrusted `.psd` can be made to write attacker-chosen bytes to an attacker-chosen path (absolute or `../`-traversing), outside its intended output directory. A secondary issue in `SmartObject.open()` for external-kind smart objects allows the attacker-controlled `fullPath` descriptor to be used as an arbitrary file read path, enabling exfiltration of the read content to the controlled write destination. Both issues are fixed in v1.17.1.
Created: 2026-09-24 Last update: 2026-09-24 01:00
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • python3-psd-tools-doc could be marked Multi-Arch: foreign
Created: 2022-11-11 Last update: 2026-09-25 02:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.1).
Created: 2022-12-17 Last update: 2026-06-25 22:30
news
[rss feed]
  • [2026-07-04] Accepted psd-tools 1.10.7+dfsg.1-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Adrian Bunk)
  • [2026-07-03] psd-tools 1.17.4+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-25] Accepted psd-tools 1.17.4+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-05-23] psd-tools 1.17.0+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-15] Accepted psd-tools 1.17.0+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-05-09] psd-tools 1.16.0+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-30] Accepted psd-tools 1.16.0+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-04-29] psd-tools 1.15.0+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-21] Accepted psd-tools 1.15.0+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-04-21] psd-tools 1.14.3+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-13] Accepted psd-tools 1.14.3+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-04-12] psd-tools 1.14.2+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-04] Accepted psd-tools 1.14.2+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2026-01-02] psd-tools 1.12.1+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-25] Accepted psd-tools 1.12.1+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2025-12-08] psd-tools 1.12.0+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-30] Accepted psd-tools 1.12.0+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2025-08-21] psd-tools 1.10.9+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-13] Accepted psd-tools 1.10.9+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2025-04-24] psd-tools 1.10.7+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-14] Accepted psd-tools 1.10.7+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2024-09-03] psd-tools 1.9.34+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-08-26] Accepted psd-tools 1.9.34+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2024-05-17] psd-tools 1.9.32+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-07] Accepted psd-tools 1.9.32+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2024-04-24] psd-tools 1.9.31+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-04-16] Accepted psd-tools 1.9.31+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2024-01-17] psd-tools 1.9.30+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-09] Accepted psd-tools 1.9.30+dfsg.1-1 (source) into unstable (Ying-Chun Liu (PaulLiu)) (signed by: Ying-Chun Liu)
  • [2023-07-11] psd-tools 1.9.28+dfsg.1-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 1
  • I&N: 0
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.17.4+dfsg.1-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing