-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 22 Mar 2026 23:52:49 +0100 Source: pymupdf Architecture: source Version: 1.25.4+ds1-3+deb13u1 Distribution: trixie Urgency: medium Maintainer: Debian Python Team Changed-By: Bastian Germann Changes: pymupdf (1.25.4+ds1-3+deb13u1) trixie; urgency=medium . * Backport upstream fix for CVE-2026-3029: Improved safety of `pymupdf embed-extract`. This now refuses to write to an existing file or outside current directory, unless `-output` or new flag `-unsafe` is specified. Checksums-Sha1: d9e0b1636719cae872dc345f07952720d1dc6737 2140 pymupdf_1.25.4+ds1-3+deb13u1.dsc 4c85e9bbe333ae6883a2a2c4e72fe769ecec9bc5 70782328 pymupdf_1.25.4+ds1.orig.tar.xz 86687529e72a4fa05e58d9613445fb34853896c8 18260 pymupdf_1.25.4+ds1-3+deb13u1.debian.tar.xz 6a41e6f472b9b2d323841689ab529d8f19a4f5f2 6797 pymupdf_1.25.4+ds1-3+deb13u1_source.buildinfo Checksums-Sha256: 6305399cb218394c35f0aa632bea9bd4daffc04dd29e971cd2867ffc5066cdcb 2140 pymupdf_1.25.4+ds1-3+deb13u1.dsc 7510eebd69b26bb20810cb2d57a4958ee5b985bff765a92a2b7a99494eace5c2 70782328 pymupdf_1.25.4+ds1.orig.tar.xz a90f8ba44206c2d80521c1c7e33b94507dfdf9120de89b3acc2fdee6f94b67f3 18260 pymupdf_1.25.4+ds1-3+deb13u1.debian.tar.xz 24cb1d50c03afdcf34b79d68c25bda973424d6bdceb5fd9d038ecfd65351ff91 6797 pymupdf_1.25.4+ds1-3+deb13u1_source.buildinfo Files: 6e4c3e9137bc9973e122ead19e4d68fc 2140 python optional pymupdf_1.25.4+ds1-3+deb13u1.dsc 9987707057762a9478b48d6f77459a36 70782328 python optional pymupdf_1.25.4+ds1.orig.tar.xz bd7a16f0b258d9bbcdf1a1dfd77fa310 18260 python optional pymupdf_1.25.4+ds1-3+deb13u1.debian.tar.xz 4fbe3959571b9f2af01a050d80b35ab0 6797 python optional pymupdf_1.25.4+ds1-3+deb13u1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQHEBAEBCgAuFiEEQGIgyLhVKAI3jM5BH1x6i0VWQxQFAmnIKmkQHGJhZ2VAZGVi aWFuLm9yZwAKCRAfXHqLRVZDFHAoC/91mUbPF03FrK5imLR/t86zxbg5oZALdQRr w2ktGJ+/2YOSi5rp4vHg+vTSiIWLXF+TmquFFlHk2rfoL/0kFMMht6GaR6k4Vjs+ eVSagaawRMlwnkTXa0AApSNtRR5RNPaCUiFaMqjNZGHzlwL7ObCtS+tOyDcvjCiG U0I1LkcdB7AaXnsmvHv4iE/ubgUS2l2o6iCo83jdIr9No38LucLH3k9Hk+bN0BQz +0M8uTmDhCu4hwZidYr4J/LC32qsIdq9kom+NsDf+gn94UlB8bJPohpdSFi4+kBz geMNlW2voFnscl1/CWGFySeoYXsvcuM/h1R5SU1o0WbLrMEQKUm2jJN8CME7lsB2 R0ysI+Hn/REJsVmJduHnazAw8u4+N2N014F1W/T8xHkqisSkRADrCT0y07s2KClp AAepQpfcpcOfJv86P7xp7La1URNk585hWIAftWrtk6AsTA/e43diQnbteXRZZOd6 XeZLTD0MidKaqQBcKmDrCKrQGsho9fc= =fWBM -----END PGP SIGNATURE-----