CVE-2024-56522

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 27, 2024
Updated: Dec 30, 2024
CWE ID 843

Summary

CVE-2024-56522 is a newly disclosed vulnerability affecting TCPDF before version 6.8.0. The issue lies in the function "unserializeTCPDFtag," which uses "!= (loose comparison)" instead of a constant-time function to compare TCPDF tag hashes. This weakness could potentially enable attackers to exploit the vulnerability by crafting maliciously crafted TCPDF files, leading to arbitrary code execution or data leakage. It is recommended that users upgrade to the latest version of TCPDF to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share