Critical severity9.8NVD Advisory· Published Sep 14, 2018· Updated Jun 17, 2026
CVE-2018-17057
CVE-2018-17057
Description
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tecnickcom/tcpdfPackagist | < 6.2.22 | 6.2.22 |
fooman/tcpdfPackagist | < 6.2.22 | 6.2.22 |
la-haute-societe/tcpdfPackagist | < 6.2.22 | 6.2.22 |
spoonity/tcpdfPackagist | < 6.2.22 | 6.2.22 |
Affected products
6- ghsa-coords4 versionspkg:composer/fooman/tcpdfpkg:composer/la-haute-societe/tcpdfpkg:composer/spoonity/tcpdfpkg:composer/tecnickcom/tcpdf
< 6.2.22+ 3 more
- (no CPE)range: < 6.2.22
- (no CPE)range: < 6.2.22
- (no CPE)range: < 6.2.22
- (no CPE)range: < 6.2.22
Patches
Vulnerability mechanics
References
15- github.com/LimeSurvey/LimeSurvey/commit/1cdd78d27697b3150bb44aaa7af1a81062a591a5nvdPatchThird Party AdvisoryWEB
- github.com/tecnickcom/TCPDF/commit/1861e33fe05f653b67d070f7c106463e7a5c26ednvdPatchThird Party AdvisoryWEB
- packetstormsecurity.com/files/152360/LimeSurvey-Deserialization-Remote-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- packetstormsecurity.com/files/152200/TCPDF-6.2.19-Deserialization-Remote-Code-Execution.htmlnvdThird Party AdvisoryVDB EntryWEB
- seclists.org/fulldisclosure/2019/Mar/36nvdMailing ListThird Party AdvisoryWEB
- contao.org/en/news/security-vulnerability-cve-2018-17057.htmlnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-5hw4-m7f3-hhx8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-17057ghsaADVISORY
- www.exploit-db.com/exploits/46634/nvdThird Party AdvisoryVDB Entry
- github.com/FriendsOfPHP/security-advisories/blob/master/fooman/tcpdf/CVE-2018-17057.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/la-haute-societe/tcpdf/CVE-2018-17057.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/spoonity/tcpdf/CVE-2018-17057.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/tecnickcom/tcpdf/CVE-2018-17057.yamlghsaWEB
- github.com/FriendsOfPHP/security-advisories/blob/master/wallabag/tcpdf/CVE-2018-17057.yamlghsaWEB
- www.exploit-db.com/exploits/46634ghsaWEB
News mentions
0No linked articles in our index yet.