Font Handling Issues in TCPDF and tc-lib-pdf-font
CVE-2024-56520
What is CVE-2024-56520?
An issue has been identified in tc-lib-pdf-font, which impacts the way fonts are managed within TCPDF and related products. Specifically, prior to the version 2.6.4 of tc-lib-pdf-font and version 6.8.0 of TCPDF, there were misparsing issues with the FontBBox for Type 1 and TrueType fonts. This flaw may lead to unexpected behaviors in documents that utilize these font types, potentially affecting the display or rendering of text within generated PDF files. Users of these affected versions are urged to update to the latest releases to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
tcpdf 0 < 6.8.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
