-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Mar 2026 16:11:43 +0900 Source: calibre Binary: calibre-bin calibre-bin-dbgsym Architecture: arm64 Version: 8.5.0+ds-1+deb13u2 Distribution: trixie Urgency: medium Maintainer: arm Build Daemon (arm-ubc-02) Changed-By: YOKOTA Hiroshi Description: calibre-bin - powerful and easy to use e-book manager (binary plugins) Changes: calibre (8.5.0+ds-1+deb13u2) trixie; urgency=medium . * CVE-2026-25635: CHM Input: Ignore internal files that have paths that end up outside the container * CVE-2026-25636: DRYer * CVE-2026-25731: ZIP Output: Change the template engine used for HTML templating from templite to Mustache, for greater safety and performance. Note that this is a breaking change if you use custom templates with ZIP output. * Use pystache instead of templite to fix CVE-2026-25731 * Add NEWS about CVE-2026-25731 fix * CVE-2026-26064: ODT Input: Ensure images are extracted within container * CVE-2026-26065: PDB Input: Ensure extracted images are within the container * CVE-2026-27810: Content server: Sanitize content disposition received as query parameter * CVE-2026-27824: Content server: When banning IPs for repeated login is enabled, only use the IP address not any HTTP headers as the ban key Checksums-Sha1: d881639bbbc0fe666a35b926d4b307930071f559 4922568 calibre-bin-dbgsym_8.5.0+ds-1+deb13u2_arm64.deb b2c51535632461cef0daf5cd9759bbcc02b641e3 832160 calibre-bin_8.5.0+ds-1+deb13u2_arm64.deb 80ad77d7a04697e8bac1516bd425653ad2d11333 24101 calibre_8.5.0+ds-1+deb13u2_arm64-buildd.buildinfo Checksums-Sha256: c5df396e9a032541c53e21243fe77453d8d75e07c65437e7afbbdb97ae3545fc 4922568 calibre-bin-dbgsym_8.5.0+ds-1+deb13u2_arm64.deb 1fa90b6a4b6e27c73c9d40026f010f276a4111a291e05498b1f270965685c532 832160 calibre-bin_8.5.0+ds-1+deb13u2_arm64.deb 4693691849162fda53055c79ac1d600dcd895dd93684cd12d30bc53bb0548303 24101 calibre_8.5.0+ds-1+deb13u2_arm64-buildd.buildinfo Files: 080b0ec22f26decda8a7f0df63e988f6 4922568 debug optional calibre-bin-dbgsym_8.5.0+ds-1+deb13u2_arm64.deb c0b420d853c8cd311579f5c5da8e71f1 832160 text optional calibre-bin_8.5.0+ds-1+deb13u2_arm64.deb 7252f2f622bd0896356bd25e8c4ab91f 24101 text optional calibre_8.5.0+ds-1+deb13u2_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEJkN0BnKzGWWW6tS+G5VHrWJmwgcFAmn2eoQACgkQG5VHrWJm wgfp7RAAzZIKOafVnGZeXPfPuzZ3kXHoJoB1S61vNAYZv9/gZH9cnRvKlbLrH+bz cpW6uwluij9vQDZxxElMtR36HefWbiYXDIJPfUBXn++s4vtrKH2RI3jk2H3Gv+ny sjKdxiacr82t8w3r6Q1c/wbR/AqeA0vSkC0fnd+0VuqNSCW8OJUxu1xJRLSU7qjX zr9DUJqhQIwGZncVQQkhCJUDsovPZog4KCd/t9adaBGY5IhFVbYef3iPcpexdFG+ QT2jBf1cE8PvxU+rbKrEnBR6ZXPxorvCqFFSUG44YCtEFcYfgdNYv+UUv2V8xar7 TkT3p+yc2sVPnyW/a6rejilzVeSY39DXHivCpjLehichYPvPZTTY8zZ/wpU6P3/B 1xGM5+xMXMJg76ZtB5IV/oj6Bwe1qhwjr2esWp/oGiBykuJ/PwvRfLHgQsKAtLN3 /mbDjEW52POyywTg4unDqShT86byVg2tHV/2d6/B8AL1RSWDgMrQ021so0abUBb5 shM871GBIUE1ruTC/ORuKHkYJyaylQG5VevLoqkOmgLSirjqOrMgT1MgYrEU/8Yv QT/IwlIxMh7f3/s+YH22Kvf04pXPZTmQXwKGRJXjAd/R+UH0O2eEOiMOlGULzP+9 aW9Lgk9xRawnKEghL+aNf9BNDm8SoHNA7ww21MMz841GtEEBUV0= =azF4 -----END PGP SIGNATURE-----