Описание
TCPDF has incorrect comparison
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2024-56522
- https://github.com/tecnickcom/TCPDF/commit/d54b97cec33f4f1a5ad81119a82085cad93cec89
- https://github.com/tecnickcom/TCPDF/compare/6.7.8...6.8.0
- https://lists.debian.org/debian-lts-announce/2025/06/msg00004.html
- https://tcpdf.org
- https://www.php.net/manual/en/types.comparisons.php
Пакеты
tecnickcom/tcpdf
< 6.8.0
6.8.0
Связанные уязвимости
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag use ...
Уязвимость PHP-класса для генерации PDF-документов TCPDF, позволяющая нарушителю обойти существующие ограничения безопасности