DEBIAN-CVE-2025-64512

Source
https://security-tracker.debian.org/tracker/CVE-2025-64512
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-64512.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-64512
Upstream
Published
2025-11-10T22:15:40.067Z
Modified
2025-11-18T05:15:29.992146Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documents. Prior to version 20251107, pdfminer.six will execute arbitrary code from a malicious pickle file if provided with a malicious PDF file. The CMapDB._load_data() function in pdfminer.six uses pickle.loads() to deserialize pickle files. These pickle files are supposed to be part of the pdfminer.six distribution stored in the cmap/ directory, but a malicious PDF can specify an alternative directory and filename as long as the filename ends in .pickle.gz. A malicious, zipped pickle file can then contain code which will automatically execute when the PDF is processed. Version 20251107 fixes the issue.

References

Affected packages

Debian:11 / pdfminer

Package

Name
pdfminer
Purl
pkg:deb/debian/pdfminer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

20200726-1
20201018+dfsg-1
20220319+dfsg-1
20221105+dfsg-1

20221105+dfsg-1.*

20221105+dfsg-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / pdfminer

Package

Name
pdfminer
Purl
pkg:deb/debian/pdfminer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

20221105+dfsg-1

20221105+dfsg-1.*

20221105+dfsg-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / pdfminer

Package

Name
pdfminer
Purl
pkg:deb/debian/pdfminer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

Other

20221105+dfsg-1

20221105+dfsg-1.*

20221105+dfsg-1.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / pdfminer

Package

Name
pdfminer
Purl
pkg:deb/debian/pdfminer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20221105+dfsg-1.1

Affected versions

Other

20221105+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}