ELA-1580-1 libssh security update
[DLA 4374-1] pdfminer security update
ELA-1580-1 libssh security update
Package : libssh
Version : 0.8.7-1+deb10u3 (buster)
Related CVEs :
CVE-2020-16135
CVE-2023-6004
CVE-2023-6918
Several vulnerabilities were discovered in libssh, a tiny C SSH library.
CVE-2020-16135
A NULL pointer dereference was found in sftpserver, which would lead
to denial of service.
CVE-2023-6004
It was reported that using the ProxyCommand or the ProxyJump feature
may allow an attacker to inject malicious code through specially
crafted hostnames.
CVE-2023-6918
Jack Weinstein reported that missing checks for return values for
digests may result in denial of service (application crashes) or
usage of uninitialized memory.ELA-1580-1 libssh security update
[SECURITY] [DLA 4374-1] pdfminer security update
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4374-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Chris Lamb
November 18, 2025 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : pdfminer
Version : 20200726-1+deb11u1
CVE ID : CVE-2025-64512
Debian Bug : 1120642
It was discovered that there was a potential arbitrary code execution
in pdfminer, a tool for extracting information from PDF documents. A
malicious, zipped pickle file could have contained code that might
have been executed when the PDF was processed.
For Debian 11 bullseye, this problem has been fixed in version
20200726-1+deb11u1.
We recommend that you upgrade your pdfminer packages.
For the detailed security status of pdfminer please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pdfminer
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS