PT-2024-19517 · Tcpdf+2 · Tcpdf+2

Zunak

·

Published

2024-05-28

·

Updated

2025-08-21

·

CVE-2024-22641

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions TCPDF versions 6.6.5 and earlier
Description The issue arises when parsing an untrusted SVG file, leading to a ReDoS (Regular Expression Denial of Service) condition. This occurs due to the inefficient handling of regular expressions within the TCPDF library, specifically when it encounters maliciously crafted SVG files. The ReDoS condition can cause the application to consume excessive resources, resulting in a denial-of-service state.
Recommendations For TCPDF versions 6.6.5 and earlier, consider updating to a version that addresses this issue, as no specific workaround is provided for these versions. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-10861
CVE-2024-22641
DLA-4199-1
DSA-5933-1
MGASA-2024-0361

Affected Products

Debian
Red Os
Tcpdf