PT-2024-36830 · Libcurl+2 · Libcurl+2

CVE-2024-56521

·

Published

2024-12-27

·

Updated

2025-02-18

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TCPDF versions prior to 6.8.0
Description An issue was discovered in TCPDF. If libcurl is used, CURLOPT SSL VERIFYHOST and CURLOPT SSL VERIFYPEER are set unsafely.
Recommendations For versions prior to 6.8.0, update to version 6.8.0 or later to resolve the issue. As a temporary workaround, consider configuring CURLOPT SSL VERIFYHOST and CURLOPT SSL VERIFYPEER safely until a patch is applied.

Exploit

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-56521
GHSA-9MGX-552F-59P6
MGASA-2025-0059

Affected Products

Debian
Tcpdf
Libcurl