Описание
Dompdf before v2.0.0 vulnerable to chroot check bypass
Dompdf prior to version 2.0.0 is vulnerable to a chroot check bypass, which could cause disclosure of png and jpeg files.
Пакеты
Наименование
dompdf/dompdf
composer
Затронутые версииВерсия исправления
< 2.0.0
2.0.0
Связанные уязвимости
CVSS3: 5.3
ubuntu
больше 3 лет назад
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
CVSS3: 5.3
nvd
больше 3 лет назад
External Control of File Name or Path in GitHub repository dompdf/dompdf prior to 2.0.0.
CVSS3: 5.3
debian
больше 3 лет назад
External Control of File Name or Path in GitHub repository dompdf/domp ...