CVE-2024-22640: High severity composer/tecnickcom/tcpdf vulnerability
Published Apr 19, 2024
·Updated
TCPDF version <= 6.7.4 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
Other sources
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
— NVD
Affected Software
3 affected componentsFixes available
composer/tecnickcom/tcpdf<=6.7.4
6.7.5
Tcpdf Project Tcpdf<=6.7.4
Fedoraproject Fedora=40
Event History
Apr 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
Description
Data Sourced
via NVD·04:15 PM
SeverityWeaknessAffected Software
Advisory Published
via GitHub·06:31 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-22640?
CVE-2024-22640 has a medium severity rating due to its potential for causing a ReDoS attack.
2
How do I fix CVE-2024-22640?
To fix CVE-2024-22640, upgrade to TCPDF version 6.7.5 or later.
3
Which versions of TCPDF are affected by CVE-2024-22640?
TCPDF versions 6.7.4 and earlier are vulnerable to CVE-2024-22640.
4
What type of attack is associated with CVE-2024-22640?
CVE-2024-22640 is associated with Regular Expression Denial of Service (ReDoS) attacks.
5
What should I do if I cannot upgrade to TCPDF 6.7.5 to mitigate CVE-2024-22640?
If you cannot upgrade, avoid parsing untrusted HTML pages with crafted colors to minimize risk from CVE-2024-22640.