PT-2014-4669 · Dompdf · Dompdf

CVE-2014-2383

·

Publicado

2014-04-28

·

Atualizado

2023-02-02

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dompdf versions prior to 0.6.1
Description The issue allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input file parameter. This can be demonstrated by using a php://filter/read=convert.base64-encode/resource in the input file parameter when DOMPDF ENABLE PHP is enabled.
Recommendations For versions prior to 0.6.1, update to version 0.6.1 or later to resolve the issue. As a temporary workaround, consider disabling the DOMPDF ENABLE PHP option to minimize the risk of exploitation. Restrict access to the input file parameter to prevent attackers from bypassing chroot protections. Avoid using the php://filter/read=convert.base64-encode/resource wrapper in the input file parameter until the issue is resolved.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-2383
GHSA-QR6Q-W4GJ-3865

Produtos afetados

Dompdf