CVE-2014-5012: Medium severity dompdf vulnerability
Published Dec 7, 2015
·Updated
Denial Of Service Vector
Other sources
DOMPDF before 0.6.2 allows denial of service.
— Launchpad
Affected Software
6 affected componentsFixes available
composer/dompdf/dompdf>=0.6, <0.6.2
0.6.2
ubuntu/php-dompdf<0.6.1+dfsg-2ubuntu1+
0.6.1+dfsg-2ubuntu1+
ubuntu/php-dompdf<0.6.2+dfsg-1, <0.6.1+dfsg-2+
0.6.2+dfsg-10.6.1+dfsg-2+
debian/php-dompdf
0.6.2+dfsg-30.6.2+dfsg-3+deb10u20.6.2+dfsg-3.12.0.3+dfsg-12.0.4+dfsg-1
composer/dompdf/dompdf>=0.6<0.6.2
0.6.2
Dompdf Project Dompdf<0.6.2
Remediation
Patch Available
Event History
Dec 7, 2015
Advisory Published
12:07 AM
Jan 10, 2020
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·05:25 AM
Data Sourced
via MITRE·05:25 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:41 PM
Description
Frequently Asked Questions
1
What is CVE-2014-5012?
CVE-2014-5012 is a vulnerability in DOMPDF before version 0.6.2 that allows for denial of service.
2
How severe is CVE-2014-5012?
CVE-2014-5012 is considered a Denial of Service (DoS) vulnerability, which can be disruptive to the availability of a system or service.
3
Which software is affected by CVE-2014-5012?
DOMPDF before 0.6.2 is affected by CVE-2014-5012.
4
How do I fix CVE-2014-5012?
To fix CVE-2014-5012, upgrade to DOMPDF version 0.6.2 or later.
5
Where can I find more information about CVE-2014-5012?
More information about CVE-2014-5012 can be found at the following references: [link 1], [link 2], [link 3].