CVE-2014-6235: High severity dompdf vulnerability
Published Sep 11, 2014
·Updated
Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary code via unknown vectors.
Affected Software
1 affected component
Kennziffer Ke Dompdf Typo3<=0.0.3
Remediation
Patch Available
Event History
Sep 11, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6235?
CVE-2014-6235 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2014-6235?
To mitigate CVE-2014-6235, upgrade the ke DomPDF extension to version 0.0.5 or later.
3
What software is affected by CVE-2014-6235?
CVE-2014-6235 affects the ke DomPDF extension for TYPO3 versions prior to 0.0.5.
4
Can CVE-2014-6235 be exploited remotely?
Yes, CVE-2014-6235 allows remote attackers to execute arbitrary code.
5
Is there a patch available for CVE-2014-6235?
Yes, a patch is available by updating the ke DomPDF extension to version 0.0.5 or higher.