CVE-2024-56522: High severity composer/tecnickcom/tcpdf vulnerability
Published Dec 27, 2024
·Updated
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
Affected Software
2 affected componentsFixes available
composer/tecnickcom/tcpdf<6.8.0
6.8.0
Tcpdf Project Tcpdf<6.8.0
Remediation
Event History
Dec 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
RemedyAffected Software
Advisory Published
via GitHub·06:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-56522?
CVE-2024-56522 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-56522?
To fix CVE-2024-56522, upgrade TCPDF to version 6.8.0 or later.
3
What does CVE-2024-56522 affect?
CVE-2024-56522 affects versions of TCPDF prior to 6.8.0.
4
What is the nature of the vulnerability in CVE-2024-56522?
CVE-2024-56522 is a vulnerability related to improper hash comparison in the unserializeTCPDFtag function.
5
Are there any known exploits for CVE-2024-56522?
As of now, there are no publicly known exploits for CVE-2024-56522.