Debian 10703 Published by

The libssh library has been updated to version 0.8.7-1+deb10u3 for Debian GNU/Linux 10 (Buster) ELTS due to several vulnerabilities, including CVE-2020-16135, which can cause a denial-of-service by triggering a NULL pointer dereference, and CVE-2023-6004, where an attacker could inject malicious code through crafted hostnames. Additionally, the library's digest checks were found lacking in CVE-2023-6918, potentially causing application crashes or usage of uninitialized memory. Meanwhile, pdfminer has also been updated to version 20200726-1+deb11u1 for Debian GNU/Linux 11 (Bullseye) LTS due to a vulnerability (CVE-2025-64512) that could allow arbitrary code execution through zipped pickle files. Users are advised to upgrade their packages and refer to the security tracker page or the wiki for more information on the updates.

ELA-1580-1 libssh security update
[DLA 4374-1] pdfminer security update




ELA-1580-1 libssh security update


Package : libssh
Version : 0.8.7-1+deb10u3 (buster)

Related CVEs :
CVE-2020-16135
CVE-2023-6004
CVE-2023-6918

Several vulnerabilities were discovered in libssh, a tiny C SSH library.

CVE-2020-16135
A NULL pointer dereference was found in sftpserver, which would lead
to denial of service.

CVE-2023-6004
It was reported that using the ProxyCommand or the ProxyJump feature
may allow an attacker to inject malicious code through specially
crafted hostnames.

CVE-2023-6918
Jack Weinstein reported that missing checks for return values for
digests may result in denial of service (application crashes) or
usage of uninitialized memory.


ELA-1580-1 libssh security update



[SECURITY] [DLA 4374-1] pdfminer security update


- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4374-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Chris Lamb
November 18, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : pdfminer
Version : 20200726-1+deb11u1
CVE ID : CVE-2025-64512
Debian Bug : 1120642

It was discovered that there was a potential arbitrary code execution
in pdfminer, a tool for extracting information from PDF documents. A
malicious, zipped pickle file could have contained code that might
have been executed when the PDF was processed.

For Debian 11 bullseye, this problem has been fixed in version
20200726-1+deb11u1.

We recommend that you upgrade your pdfminer packages.

For the detailed security status of pdfminer please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pdfminer

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS