{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"Medium"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"python-pdfminer.six security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for python-pdfminer.six is now available for openEuler-24.03-LTS-SP3",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"PDF parser and analyzer.\n\nSecurity Fix(es):\n\npdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.(CVE-2025-70559)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for python-pdfminer.six is now available for master/openEuler-24.03-LTS/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP2/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"Medium",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"python-pdfminer.six",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2026-4210",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4210"
			},
			{
				"summary":"CVE-2025-70559",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-70559&packageName=python-pdfminer.six"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-70559"
			},
			{
				"summary":"openEuler-SA-2026-4210 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2026/csaf-openeuler-sa-2026-4210.json"
			}
		],
		"title":"An update for python-pdfminer.six is now available for openEuler-24.03-LTS-SP3",
		"tracking":{
			"initial_release_date":"2026-10-08T09:39:41+08:00",
			"revision_history":[
				{
					"date":"2026-10-08T09:39:41+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-10-08T09:39:41+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-10-08T09:39:41+08:00",
			"id":"openEuler-SA-2026-4210",
			"version":"1.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"openEuler-24.03-LTS-SP3",
									"name":"openEuler-24.03-LTS-SP3"
								},
								"name":"openEuler-24.03-LTS-SP3",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python-pdfminer.six-20231228-4.oe2403sp3.src.rpm",
									"name":"python-pdfminer.six-20231228-4.oe2403sp3.src.rpm"
								},
								"name":"python-pdfminer.six-20231228-4.oe2403sp3.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python-pdfminer.six-help-20231228-4.oe2403sp3.noarch.rpm",
									"name":"python-pdfminer.six-help-20231228-4.oe2403sp3.noarch.rpm"
								},
								"name":"python-pdfminer.six-help-20231228-4.oe2403sp3.noarch.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP3"
									},
									"product_id":"python3-pdfminer.six-20231228-4.oe2403sp3.noarch.rpm",
									"name":"python3-pdfminer.six-20231228-4.oe2403sp3.noarch.rpm"
								},
								"name":"python3-pdfminer.six-20231228-4.oe2403sp3.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python-pdfminer.six-20231228-4.oe2403sp3.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python-pdfminer.six-20231228-4.oe2403sp3.src",
					"name":"python-pdfminer.six-20231228-4.oe2403sp3.src as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python-pdfminer.six-help-20231228-4.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python-pdfminer.six-help-20231228-4.oe2403sp3.noarch",
					"name":"python-pdfminer.six-help-20231228-4.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP3",
				"product_reference":"python3-pdfminer.six-20231228-4.oe2403sp3.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP3:python3-pdfminer.six-20231228-4.oe2403sp3.noarch",
					"name":"python3-pdfminer.six-20231228-4.oe2403sp3.noarch as a component of openEuler-24.03-LTS-SP3"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2025-70559",
			"notes":[
				{
					"text":"pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-24.03-LTS-SP3:python-pdfminer.six-20231228-4.oe2403sp3.src",
					"openEuler-24.03-LTS-SP3:python-pdfminer.six-help-20231228-4.oe2403sp3.noarch",
					"openEuler-24.03-LTS-SP3:python3-pdfminer.six-20231228-4.oe2403sp3.noarch"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-24.03-LTS-SP3:python-pdfminer.six-20231228-4.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python-pdfminer.six-help-20231228-4.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-pdfminer.six-20231228-4.oe2403sp3.noarch"
					],
					"details":"python-pdfminer.six security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4210"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":6.5,
						"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
						"version":"3.1"
					},
					"products":[
						"openEuler-24.03-LTS-SP3:python-pdfminer.six-20231228-4.oe2403sp3.src",
						"openEuler-24.03-LTS-SP3:python-pdfminer.six-help-20231228-4.oe2403sp3.noarch",
						"openEuler-24.03-LTS-SP3:python3-pdfminer.six-20231228-4.oe2403sp3.noarch"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2025-70559"
		}
	]
}