CVE-2014-5011: Infoleak
Published Dec 7, 2015
·Updated
Information Disclosure
Affected Software
6 affected componentsFixes available
composer/dompdf/dompdf>=0.6, <0.6.2
0.6.2
ubuntu/php-dompdf<0.6.1+dfsg-2ubuntu1+
0.6.1+dfsg-2ubuntu1+
ubuntu/php-dompdf<0.6.2+dfsg-1, <0.6.1+dfsg-2+
0.6.2+dfsg-10.6.1+dfsg-2+
debian/php-dompdf
0.6.2+dfsg-30.6.2+dfsg-3+deb10u20.6.2+dfsg-3.12.0.3+dfsg-12.0.4+dfsg-1
composer/dompdf/dompdf>=0.6<0.6.2
0.6.2
Dompdf Project Dompdf<0.6.2
Remediation
Patch Available
Event History
Dec 7, 2015
Advisory Published
12:07 AM
Jan 10, 2020
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·05:25 AM
Data Sourced
via MITRE·05:25 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:41 PM
Description
Frequently Asked Questions
1
What is CVE-2014-5011?
CVE-2014-5011 is a vulnerability that allows information disclosure in DOMPDF before version 0.6.2.
2
How severe is CVE-2014-5011?
CVE-2014-5011 has a severity rating of 6.5 (medium).
3
Which software is affected by CVE-2014-5011?
CVE-2014-5011 affects DOMPDF versions before 0.6.2 and packages including dompdf, dompdf/dompdf, php-dompdf, ubuntu/php-dompdf, and debian/php-dompdf.
4
How can I fix CVE-2014-5011?
To fix CVE-2014-5011, make sure to update your DOMPDF installation to version 0.6.2 or later.
5
Where can I find more information about CVE-2014-5011?
More information about CVE-2014-5011 can be found at the following references: [Link 1](https://github.com/dompdf/dompdf/compare/v0.6.1...v0.6.2), [Link 2](https://github.com/dompdf/dompdf/releases/tag/v0.6.2), and [Link 3](https://launchpad.net/bugs/cve/CVE-2014-5011).