PT-2024-36830 · Libcurl+2 · Libcurl+2

Published

2024-12-27

·

Updated

2025-02-18

·

CVE-2024-56521

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TCPDF versions prior to 6.8.0
Description An issue was discovered in TCPDF. If libcurl is used, CURLOPT SSL VERIFYHOST and CURLOPT SSL VERIFYPEER are set unsafely.
Recommendations For versions prior to 6.8.0, update to version 6.8.0 or later to resolve the issue. As a temporary workaround, consider configuring CURLOPT SSL VERIFYHOST and CURLOPT SSL VERIFYPEER safely until a patch is applied.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2024-56521
GHSA-9MGX-552F-59P6
MGASA-2025-0059

Affected Products

Debian
Tcpdf
Libcurl