CVE-2024-56520
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Dec 27, 2024
Updated: Jan 2, 2025
Summary
CVE-2024-56520 is a newly disclosed vulnerability that affects tc-lib-pdf-font versions prior to 2.6.4, as used in TCPDF before 6.8.0, and other products. The flaw lies in the font handling mechanism, specifically in the parsing of FontBBox for Type 1 and TrueType fonts, which can lead to potential security risks. Misparsed font data can result in unexpected application behavior or even arbitrary code execution. Users are strongly advised to update their affected software to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.