PT-2014-4669 · Dompdf · Dompdf

Published

2014-04-28

·

Updated

2023-02-02

·

CVE-2014-2383

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions dompdf versions prior to 0.6.1
Description The issue allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input file parameter. This can be demonstrated by using a php://filter/read=convert.base64-encode/resource in the input file parameter when DOMPDF ENABLE PHP is enabled.
Recommendations For versions prior to 0.6.1, update to version 0.6.1 or later to resolve the issue. As a temporary workaround, consider disabling the DOMPDF ENABLE PHP option to minimize the risk of exploitation. Restrict access to the input file parameter to prevent attackers from bypassing chroot protections. Avoid using the php://filter/read=convert.base64-encode/resource wrapper in the input file parameter until the issue is resolved.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2014-2383
GHSA-QR6Q-W4GJ-3865

Affected Products

Dompdf