PT-2024-36831 · Tcpdf+2 · Tcpdf+2

Published

2024-12-27

·

Updated

2025-08-21

·

CVE-2024-56522

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions TCPDF versions prior to 6.8.0
Description An issue was discovered in the unserializeTCPDFtag function, which uses loose comparison (!=) and does not utilize a constant-time function to compare TCPDF tag hashes. This could potentially lead to security issues.
Recommendations For versions prior to 6.8.0, update to version 6.8.0 or later to resolve the issue. As a temporary workaround, consider disabling the unserializeTCPDFtag function until a patch is available.

Fix

Type Confusion

Weakness Enumeration

Related Identifiers

BDU:2025-10830
CVE-2024-56522
DLA-4199-1
DSA-5933-1
GHSA-W95C-7994-GHPR
MGASA-2025-0059

Affected Products

Debian
Red Os
Tcpdf