CVE-2017-6100: High severity Tcpdf Project Tcpdf vulnerability
tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tcpdfto a version that resolves this vulnerability.Fixed in 6.3.5+dfsg1-1Fixed in 6.6.2+dfsg1-1Fixed in 6.7.5+dfsg-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6100?
CVE-2017-6100 has been rated as a medium severity vulnerability due to its potential for unauthorized file uploads.
How do I fix CVE-2017-6100?
To fix CVE-2017-6100, upgrade TCPDF to version 6.2.0 or later to eliminate the vulnerability.
What versions of TCPDF are affected by CVE-2017-6100?
CVE-2017-6100 affects versions of TCPDF prior to 6.2.0, including 6.1.1 and all earlier versions.
What type of vulnerability is CVE-2017-6100?
CVE-2017-6100 is a vulnerability that allows unauthorized file uploads from the server generating PDF files to an external FTP.
Is CVE-2017-6100 related to any specific operating systems?
CVE-2017-6100 is particularly relevant for users of Debian systems running outdated versions of TCPDF.