Mageia alert MGASA-2025-0059 (php-tcpdf)
From: | Mageia Updates <updates-announce@ml.mageia.org> | |
To: | updates-announce@ml.mageia.org | |
Subject: | [updates-announce] MGASA-2025-0059: Updated php-tcpdf packages fix security vulnerabilities | |
Date: | Wed, 12 Feb 2025 22:32:17 +0100 | |
Message-ID: | <20250212213217.788D69FC85@duvel.mageia.org> | |
Archive-link: | Article |
MGASA-2025-0059 - Updated php-tcpdf packages fix security vulnerabilities Publication date: 12 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0059.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-56519, CVE-2024-56521, CVE-2024-56522, CVE-2024-56527 Description: An issue was discovered in TCPDF before 6.8.0. setSVGStyles does not sanitize the SVG font-family attribute. (CVE-2024-56519) An issue was discovered in TCPDF before 6.8.0. If libcurl is used, CURLOPT_SSL_VERIFYHOST and CURLOPT_SSL_VERIFYPEER are set unsafely. (CVE-2024-56521) An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes. (CVE-2024-56522) An issue was discovered in TCPDF before 6.8.0. The Error function lacks an htmlspecialchars call for the error message. (CVE-2024-56527) References: - https://bugs.mageia.org/show_bug.cgi?id=33898 - https://lists.fedoraproject.org/archives/list/package-ann... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5... - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-5... SRPMS: - 9/core/php-tcpdf-6.5.0-1.3.mga9