Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-2383

Опубликовано: 28 апр. 2014
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 6.8

Описание

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.

РелизСтатусПримечание
artful

not-affected

0.6.1+dfsg-2
bionic

not-affected

0.6.1+dfsg-2
cosmic

not-affected

0.6.1+dfsg-2
devel

not-affected

0.6.1+dfsg-2
disco

not-affected

0.6.1+dfsg-2
esm-apps/bionic

not-affected

0.6.1+dfsg-2
esm-apps/xenial

not-affected

0.6.1+dfsg-2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
lucid

DNE

precise

DNE

Показывать по

EPSS

Процентиль: 98%
0.5489
Средний

6.8 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.

debian
почти 12 лет назад

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, ...

github
больше 3 лет назад

DOMPDF Arbitrary File Read

EPSS

Процентиль: 98%
0.5489
Средний

6.8 Medium

CVSS2