Denial of Service Vulnerability in DOMPDF Software by Dominik Homberger
CVE-2014-5012

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
10 January 2020

What is CVE-2014-5012?

A vulnerability exists in DOMPDF, which is an open-source library used for converting HTML to PDF. Versions before 0.6.2 are susceptible to a denial of service attack. This flaw could be exploited by crafting specific inputs that disrupt the normal processing of the software, potentially leading to application downtime or degraded performance. It is imperative for users to upgrade to the latest version to mitigate this risk and secure their applications.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2014-5012 : Denial of Service Vulnerability in DOMPDF Software by Dominik Homberger