PT-2024-19517 · Tcpdf+2 · Tcpdf+2
Zunak
·
Published
2024-05-28
·
Updated
2025-08-21
·
CVE-2024-22641
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
TCPDF versions 6.6.5 and earlier
Description
The issue arises when parsing an untrusted SVG file, leading to a ReDoS (Regular Expression Denial of Service) condition. This occurs due to the inefficient handling of regular expressions within the TCPDF library, specifically when it encounters maliciously crafted SVG files. The ReDoS condition can cause the application to consume excessive resources, resulting in a denial-of-service state.
Recommendations
For TCPDF versions 6.6.5 and earlier, consider updating to a version that addresses this issue, as no specific workaround is provided for these versions.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Red Os
Tcpdf