First published: Mon Dec 07 2015(Updated: )
Information Disclosure
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/dompdf/dompdf | >=0.6<0.6.2 | 0.6.2 |
ubuntu/php-dompdf | <0.6.1+dfsg-2ubuntu1+ | 0.6.1+dfsg-2ubuntu1+ |
ubuntu/php-dompdf | <0.6.2+dfsg-1<0.6.1+dfsg-2+ | 0.6.2+dfsg-1 0.6.1+dfsg-2+ |
debian/php-dompdf | 0.6.2+dfsg-3 0.6.2+dfsg-3+deb10u2 0.6.2+dfsg-3.1 2.0.3+dfsg-1 2.0.4+dfsg-1 | |
composer/dompdf/dompdf | >=0.6<0.6.2 | 0.6.2 |
Dompdf | <0.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-5011 is a vulnerability that allows information disclosure in DOMPDF before version 0.6.2.
CVE-2014-5011 has a severity rating of 6.5 (medium).
CVE-2014-5011 affects DOMPDF versions before 0.6.2 and packages including dompdf, dompdf/dompdf, php-dompdf, ubuntu/php-dompdf, and debian/php-dompdf.
To fix CVE-2014-5011, make sure to update your DOMPDF installation to version 0.6.2 or later.
More information about CVE-2014-5011 can be found at the following references: [Link 1](https://github.com/dompdf/dompdf/compare/v0.6.1...v0.6.2), [Link 2](https://github.com/dompdf/dompdf/releases/tag/v0.6.2), and [Link 3](https://launchpad.net/bugs/cve/CVE-2014-5011).