Critical severityNVD Advisory· Published Sep 14, 2018· Updated Aug 5, 2024
CVE-2018-17057
CVE-2018-17057
Description
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tecnickcom/tcpdfPackagist | < 6.2.22 | 6.2.22 |
fooman/tcpdfPackagist | < 6.2.22 | 6.2.22 |
la-haute-societe/tcpdfPackagist | < 6.2.22 | 6.2.22 |
spoonity/tcpdfPackagist | < 6.2.22 | 6.2.22 |
Affected products
4- ghsa-coords4 versionspkg:composer/fooman/tcpdfpkg:composer/la-haute-societe/tcpdfpkg:composer/spoonity/tcpdfpkg:composer/tecnickcom/tcpdf
< 6.2.22+ 3 more
- (no CPE)range: < 6.2.22
- (no CPE)range: < 6.2.22
- (no CPE)range: < 6.2.22
- (no CPE)range: < 6.2.22
Patches
Vulnerability mechanics
References
15- www.exploit-db.com/exploits/46634/mitreexploitx_refsource_EXPLOIT-DB
- github.com/advisories/GHSA-5hw4-m7f3-hhx8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-17057ghsaADVISORY
- packetstormsecurity.com/files/152200/TCPDF-6.2.19-Deserialization-Remote-Code-Execution.htmlghsax_refsource_MISCWEB
- packetstormsecurity.com/files/152360/LimeSurvey-Deserialization-Remote-Code-Execution.htmlghsax_refsource_MISCWEB
- seclists.org/fulldisclosure/2019/Mar/36ghsamailing-listx_refsource_FULLDISCWEB
- contao.org/en/news/security-vulnerability-cve-2018-17057.htmlghsax_refsource_MISCWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/fooman/tcpdf/CVE-2018-17057.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/la-haute-societe/tcpdf/CVE-2018-17057.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/spoonity/tcpdf/CVE-2018-17057.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/tecnickcom/tcpdf/CVE-2018-17057.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/wallabag/tcpdf/CVE-2018-17057.yamlghsaWEB
- github.com/LimeSurvey/LimeSurvey/commit/1cdd78d27697b3150bb44aaa7af1a81062a591a5ghsax_refsource_MISCWEB
- github.com/tecnickcom/TCPDF/commit/1861e33fe05f653b67d070f7c106463e7a5c26edghsax_refsource_MISCWEB
- www.exploit-db.com/exploits/46634ghsaWEB
News mentions
0No linked articles in our index yet.