Back Linuxsecurity Ubuntu 24.04 LTS pdfminer Important Code Execution Risk USN-8837
CISA confirms exploitation of a Linux firewall flaw. Check if your systems need the fix. ×
pdfminer could be made to run programs as your login if it opened a specially crafted file. Software Description: - pdfminer: PDF parser and analyser Details: It was discovered that pdfminer did not safely parse specially crafted PDF files. An attacker could possibly use these issues to execute arbitrary code. (CVE-2025-64512, CVE-2025-70559)
pdfminer could be made to run programs as your login if it opened a
specially crafted file.
Software Description:
- pdfminer: PDF parser and analyser
It was discovered that pdfminer did not safely parse specially crafted
PDF files. An attacker could possibly use these issues to execute
arbitrary code. (CVE-2025-64512, CVE-2025-70559)
The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python3-pdfminer 20221105+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-pdfminer 20220319+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS python3-pdfminer 20191020+dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS python-pdfminer 20140328+dfsg-1ubuntu0.18.04.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS python-pdfminer 20140328+dfsg-1ubuntu0.16.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
CVE-2025-64512, CVE-2025-70559
Ubuntu Security Notice USN-8837-1
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
