Loose Comparison Vulnerability in TCPDF Affects Document Generation Security
CVE-2024-56522

7.5HIGH

Key Information:

Vendor

Tecnick

Status
Vendor
CVE Published:
27 December 2024

What is CVE-2024-56522?

A vulnerability has been identified in TCPDF, affecting versions prior to 6.8.0. The issue arises from the unserializeTCPDFtag function, which employs loose comparison (using '!=') rather than a strict comparison method. This approach can lead to security weaknesses as it fails to utilize a constant-time function for comparing TCPDF tag hashes. The lack of a robust comparison technique may allow attackers to exploit this characteristic, thereby compromising the integrity of documents generated using TCPDF. Security updates in version 6.8.0 address this issue, reinforcing the need for users to upgrade and ensure their document generation practices remain secure.

Affected Version(s)

tcpdf 0 < 6.8.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.