From nobody Mon Nov 17 07:27:08 2025 X-Original-To: dev-commits-ports-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4d8zpP1MdMz6GlM7; Mon, 17 Nov 2025 07:27:09 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4d8zpP0Nfbz3ZMf; Mon, 17 Nov 2025 07:27:09 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1763364429; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=0dybffut059/HSuuLZ2iPpiToI20tcIAH0rtRbUOdFs=; b=cf0nlZrSlHH1S3BcMz3wd8VQ+O0ZB+c8mEslax83q/2r+tJ7wd0c3al8sWcWqwAshqLUro tg8L8sDjdOrCQroTAdivKfcFlhVmmNdkk5fxbox1b/BGAMiSXEmEEbtNF0THF89W+H/U6h GcmB2uKC9+1ifqXoQlGX6Y5jVOTDk+OXf+Q83GfeWo+WQnwrYY0QP3k0BrxmiMeS7NgJDW PLJvJVkF84gs3y6RmMez8OR09wp6ZLMArz3gAUSa782/V9yOWKtBWujPlapJYFzRUjh/Gn B30vQF0dk3tywlTbFA4OkwEYLXoh/OO1ibSm6NkRXGAZR2mhn2x5qW7X5EchkA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1763364429; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=0dybffut059/HSuuLZ2iPpiToI20tcIAH0rtRbUOdFs=; b=nAgSgbcdojb2QQxacJRrvYClBV4UhX69xAWNDJYVupOWqd528qtR+oejcL9pSsc10ukfRi I7OM8dBJ1Vf9q9ZbkpSAnB33oUmOyizY6Xd6MuGHSCSEzFgu9K+C9A1Exh31C8M01rNxAU EVC1D+WrvTMifcVjlOfCpu+IPvYRXjH1Tq6PNC53h9cioi25xxinEUThvYksQLeMXe65yE nz8YMfjduZnl0FVTwlNUScHM2fADH/RETkPUSyJcs+M4Sf9Gz1bGLorrAbhdQTqdOLebJW zcpZKBO00g9CbGmZTdJaBkjO3R3y4QdGGufRiFAKwy9J/+ZbC8t3hca/TgPxtQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1763364429; a=rsa-sha256; cv=none; b=pd/7RAVPO25ewiP4ZH6LgFIMxrK6jMwKYfibid2VafYxxcVbu5xxxuiheJkdOj8oktP+7F umH5zst/9FIVKKqSqwGxjNnijqceWX+pFzR6N97Jz3PvEmmDEt4PUEBY+wEp8IOgZ3XeBM /z3xsdqbcNsEnGCI8nfn0SjhqPNoxkh8IpVNgM2tfshyImVLGpGWdlFZpQs+QU2sJsfrnS fC9wICeMwN055OjP4u73Ihst8G4iXDnGHnw+LwJs5MG+QFKOI9x67nAIOMURyOcjblL/la nKBHCNLigs266w4d3h0depNLiTtpWxkiwciw91sJJMlH5zSTnH3JBFg7qffXKg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4d8zpN6q0xz1DcB; Mon, 17 Nov 2025 07:27:08 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.18.1/8.18.1) with ESMTP id 5AH7R8Ek073268; Mon, 17 Nov 2025 07:27:08 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.18.1/8.18.1/Submit) id 5AH7R8jE073265; Mon, 17 Nov 2025 07:27:08 GMT (envelope-from git) Date: Mon, 17 Nov 2025 07:27:08 GMT Message-Id: <202511170727.5AH7R8jE073265@gitrepo.freebsd.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org From: Kai Knoblich Subject: git: 7bbae4233dc6 - main - security/vuxml: Document py-pdfminer.six security issue List-Id: Commits to the main branch of the FreeBSD ports repository List-Archive: https://lists.freebsd.org/archives/dev-commits-ports-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-ports-main@freebsd.org Sender: owner-dev-commits-ports-main@FreeBSD.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kai X-Git-Repository: ports X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 7bbae4233dc64e73311563a433a68eb3148340d4 Auto-Submitted: auto-generated The branch main has been updated by kai: URL: https://cgit.FreeBSD.org/ports/commit/?id=7bbae4233dc64e73311563a433a68eb3148340d4 commit 7bbae4233dc64e73311563a433a68eb3148340d4 Author: Kai Knoblich AuthorDate: 2025-11-17 07:21:21 +0000 Commit: Kai Knoblich CommitDate: 2025-11-17 07:25:03 +0000 security/vuxml: Document py-pdfminer.six security issue * CVE-2025-64512 - 8.6 --- security/vuxml/vuln/2025.xml | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/security/vuxml/vuln/2025.xml b/security/vuxml/vuln/2025.xml index 6fa3610be43d..311e55693be2 100644 --- a/security/vuxml/vuln/2025.xml +++ b/security/vuxml/vuln/2025.xml @@ -1,3 +1,34 @@ + + py-pdfminer.six -- Arbitrary Code Execution in pdfminer.six via Crafted PDF Input + + + py310-pdfminer.six + py311-pdfminer.six + py312-pdfminer.six + py313-pdfminer.six + py313t-pdfminer.six + py314-pdfminer.six + 20251107 + + + + +

Pieter Marsman reports:

+
+

pdfminer.six will execute arbitrary code from a malicious pickle file if provided with a malicious PDF file. The CMapDB._load_data() function in pdfminer.six uses pickle.loads() to deserialize pickle files. These pickle files are supposed to be part of the pdfminer.six distribution stored in the cmap/ directory, but a malicious PDF can specify an alternative directory and filename as long as the filename ends in .pickle.gz. A malicious, zipped pickle file can then contain code which will automatically execute when the PDF is processed.

+
+ +
+ + CVE-2025-64512 + https://nvd.nist.gov/vuln/detail/CVE-2025-64512 + + + 2025-11-07 + 2025-11-17 + +
+ sudo-rs -- Authenticating user not recorded properly in timestamp