MGASA-2024-0361 - Updated php-tcpdf packages fix security vulnerability

Publication date: 12 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0361.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2024-22641

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular
Expression Denial of Service) if parsing an untrusted SVG file.
(CVE-2024-22641)

References:
- https://bugs.mageia.org/show_bug.cgi?id=33731
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WGK7LQSJONZPU3VOQTQ36UN6OAD6ZM4H/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22641

SRPMS:
- 9/core/php-tcpdf-6.5.0-1.2.mga9

Mageia 2024-0361: php-tcpdf Security Advisory Updates

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file

Summary

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. (CVE-2024-22641)

References

- https://bugs.mageia.org/show_bug.cgi?id=33731

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WGK7LQSJONZPU3VOQTQ36UN6OAD6ZM4H/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-22641

Resolution

MGASA-2024-0361 - Updated php-tcpdf packages fix security vulnerability

SRPMS

- 9/core/php-tcpdf-6.5.0-1.2.mga9

Severity
Publication date: 12 Nov 2024
URL: https://advisories.mageia.org/MGASA-2024-0361.html
Type: security
CVE: CVE-2024-22641

Related News