-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4744-1                [email protected]
https://www.debian.org/lts/security/                          Abhijith PA
August 18, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : calibre
Version        : 6.13.0+repack-2+deb12u10
CVE ID         : CVE-2026-53511

It was discovered that a malicious EPUB, OPF or PDF file can execute
arbitrary Python code when its metadata is read by calibre, an e-book
manager.

There was a regression introduced by the fix of CVE-2026-25636. It is
also fixed in this update.

For Debian 12 bookworm, this problem has been fixed in version
6.13.0+repack-2+deb12u10.

We recommend that you upgrade your calibre packages.

For the detailed security status of calibre please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/calibre

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqD9pIACgkQhj1N8u2c
KO/rZw//SDm/0Uy434zqJv42c9Kfq6IznIq+CTia4u1C7MdaYjBqhBukXNCbNf+n
KGRzCCIUTX290yTjEzeq66+nsikJTE4NtJN6BDGWYqiP/VGL7Tzg3HblqxbdhMI6
aV3AxFwG6Dw9j9Pd/JrPiMHAolfwS2db69gLeUa5erRPgn9ybC4ZqdIf1qxer9rK
4rEBnSLvznnNS+ir5WY6pPUOoDOhxNvdrsJ9f90T/K6bPG2PCUyBWUu0JBu62Hux
YoYir1iXubHIwgeQsL1uxZAqIRvd1evdg15QLc/fNwich0CiPJ5YhikxN+JRVP5q
AtzZmZZEyPiyzx/f4QirN1yu8P3h2grIY5LQt0lKrLuExv8JK3EFC75rEUz8nSet
t9m/HB5mH8QbcdSzmA+BmR+iYNsBTWnP0c1stJhtH+CDE7er5y5JFK+cPeWul6/v
bdHfHEvRQQfvDFVdVETXxBlG8ZT0iTRuir8zE2BIgLKvYxnCzycZfTko9pc8agy4
pn2djnhxIxCHpLPnDIvb2StZlXau1ru2BE7v5jId43wEuw3Jm0y8CWjDKJUCFRZZ
laGJajia6Oxt6CmDTfiTHUzbnDtY+/mQ3kEQ0Q+LRG8XXZ8qeoBHLW9zXREKkWJk
hB4Fu5vYWtS0Jbh+8JYcJtWbOZjh6gXPOSRcFDoV4JBxeHbPCqU=
=V4bj
-----END PGP SIGNATURE-----

Reply via email to