CVE-2022-2400: External Control of File Name or Path in dompdf/dompdf
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-2400?
CVE-2022-2400 is a vulnerability that allows an attacker to control the file name or path in the GitHub repository dompdf/dompdf prior to version 2.0.0.
Which software versions are affected by CVE-2022-2400?
Versions 0.6.2+dfsg-3+deb10u2, 2.0.3+dfsg-1, and 2.0.3+dfsg-3 of the debian/php-dompdf package are affected. Version 2.0.0 of the ubuntu/php-dompdf package is also affected.
How can I fix CVE-2022-2400 in debian/php-dompdf?
To fix CVE-2022-2400 in debian/php-dompdf, update to version 0.6.2+dfsg-3.1 or later.
How can I fix CVE-2022-2400 in ubuntu/php-dompdf?
To fix CVE-2022-2400 in ubuntu/php-dompdf, update to version 2.0.0 or later.
Where can I find more information about CVE-2022-2400?
More information about CVE-2022-2400 can be found in the references: [link1](https://huntr.dev/bounties/a6da5e5e-86be-499a-a3c3-2950f749202a), [link2](https://github.com/dompdf/dompdf/commit/99aeec1efec9213e87098d42eb09439e7ee0bb6a), [link3](https://lists.debian.org/debian-lts-announce/2023/07/msg00017.html).