Логотип exploitDog
bind:CVE-2025-70559
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-70559

Количество 4

Количество 4

ubuntu логотип

CVE-2025-70559

5 дней назад

pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.

EPSS: Низкий
nvd логотип

CVE-2025-70559

5 дней назад

pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.

EPSS: Низкий
debian логотип

CVE-2025-70559

5 дней назад

pdfminer.six before 20251230 contains an insecure deserialization vuln ...

EPSS: Низкий
github логотип

GHSA-f83h-ghpp-7wcc

3 месяца назад

Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-70559

pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.

0%
Низкий
5 дней назад
nvd логотип
CVE-2025-70559

pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The library uses Python pickle to deserialize CMap cache files without validation. An attacker with the ability to place a malicious pickle file in a location accessible to the application can trigger arbitrary code execution or privilege escalation when the file is loaded by a trusted process. This is caused by an incomplete patch to CVE-2025-64512.

0%
Низкий
5 дней назад
debian логотип
CVE-2025-70559

pdfminer.six before 20251230 contains an insecure deserialization vuln ...

0%
Низкий
5 дней назад
github логотип
GHSA-f83h-ghpp-7wcc

Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc

CVSS3: 7.8
0%
Низкий
3 месяца назад

Уязвимостей на страницу