-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 01 Mar 2026 16:14:12 +0900 Source: calibre Binary: calibre-bin calibre-bin-dbgsym Architecture: amd64 Version: 6.13.0+repack-2+deb12u6 Distribution: bookworm Urgency: medium Maintainer: amd64 / i386 Build Daemon (x86-csail-01) Changed-By: YOKOTA Hiroshi Description: calibre-bin - powerful and easy to use e-book manager (binary plugins) Changes: calibre (6.13.0+repack-2+deb12u6) bookworm; urgency=medium . * CVE-2026-25635: CHM Input: Ignore internal files that have paths that end up outside the container * CVE-2026-25636: DRYer * CVE-2026-25731: ZIP Output: Change the template engine used for HTML templating from templite to Mustache, for greater safety and performance. Note that this is a breaking change if you use custom templates with ZIP output. * Use pystache instead of templite to fix CVE-2026-25731 * Add NEWS about CVE-2026-25731 fix * CVE-2026-26064: ODT Input: Ensure images are extracted within container * CVE-2026-26065: PDB Input: Ensure extracted images are within the container * CVE-2026-27810: Content server: Sanitize content disposition received as query parameter * CVE-2026-27824: Content server: When banning IPs for repeated login is enabled, only use the IP address not any HTTP headers as the ban key Checksums-Sha1: 5bbd0c535ed9c90410438f0aac488017bb788f00 4543548 calibre-bin-dbgsym_6.13.0+repack-2+deb12u6_amd64.deb 8234e6b06b4b8a444f1712fad9b63520d721336c 851640 calibre-bin_6.13.0+repack-2+deb12u6_amd64.deb 0f5a655e7f5ec33796391e5608c32a0e90b71d8e 18207 calibre_6.13.0+repack-2+deb12u6_amd64-buildd.buildinfo Checksums-Sha256: e4710975b125322877329efbe55147a0adffcec6a0972d871e6b9301377d7153 4543548 calibre-bin-dbgsym_6.13.0+repack-2+deb12u6_amd64.deb d0ce76c72b98a528eff345da722a5974b5f736d0cf05adc907997aa3fbad4f1b 851640 calibre-bin_6.13.0+repack-2+deb12u6_amd64.deb bd9a3f07126e790b3fef3731237e9435564144b31438c147d959165c8abd5623 18207 calibre_6.13.0+repack-2+deb12u6_amd64-buildd.buildinfo Files: e43258352c8ea0b24a3d930865e9c4c7 4543548 debug optional calibre-bin-dbgsym_6.13.0+repack-2+deb12u6_amd64.deb 48d17a8fdc5240763e87638b78eaca4d 851640 text optional calibre-bin_6.13.0+repack-2+deb12u6_amd64.deb 052f6241f7d3b71e4dab7c82e6f7dd5b 18207 text optional calibre_6.13.0+repack-2+deb12u6_amd64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEBDWXQb2umOtH4DRpYg9P9sm2dfEFAmn2dJ0ACgkQYg9P9sm2 dfHzHA/+JcSgbRFYzpaOc4QWChLrGyXZyfn+m7DYARo8C77GVJRhBMBJlSWjtRkK v7BYQBnMocxPnd4aBn3iwepohM8X7yT/jSDlOfRlqDAZ+M6GPQwRg02ZTUsGFQR8 npZixU+0fKhs8dCi/sdd9CCEXDNmi2n7x5u9lr2M50ANCKlgx+JSqvcidEV4edAN w9EKIInV/6MTgur0FDSb1R60YVCwJL7Wg9qVVaY0c75OnzubJG9nsNkWWTn3Pw8E pDQ9vkeG6qOMYpp+UjIQqmrg42K/wQQIYjVmY7+pvuYTMIP+FFjdjqhfhR/VUsMy F6+h8vDU/MxBMUKRYHJ+TN00bXD9LckbxLxw1XuC3OkIS5AE9oduLJ/WRwZ6bfwI 6kjuSnAU66m5AXXyNN/VYsYbr95fyHxKx+cw1mjBrx0is+nClXUivmTnH7gBb4g/ /e6po5Ua/ubeYWNeEW7IKmmWiISrN+JnuneciuIA8zR0OztYdvovQPna8Ycn1BIN mIo2uiKhKNyH2hfR7yX6+Jwu1JrVJ313bKspA3vWluT71PyVwywyeCEKs1WORQHJ RjOJBPuqcOzUHF0M9PtMfYqsPgpvq7/UWXnOtY+vHRpHbODfV+ffPXgu8v7npivG UMCUMwSgBt4nrpHogOb3vFH8x7JUoIh+BMFFHFj6F4Iqz0dTAh0= =s2Id -----END PGP SIGNATURE-----