Intel

AIKIDO-2024-10348

fooman/tcpdf is vulnerable to Regular Expression Denial of Service (ReDoS)

Regular Expression Denial of Service (ReDoS)CSV-2024-22640 Published Oct 18, 2024

62

Medium Risk

This Affects:

phpfooman/tcpdf
2.0.0 - 6.7.4
Fixed in 6.7.5
Are you affected? Scan for Free

TL;DR

Affected versions of the package are vulnerable to Regular Expression Denial of Service (ReDoS) when a malicious color value is passed to the convertHTMLColorToDec() function.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

fooman/tcpdf is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.0.0 - 6.7.4.

How to fix this

Upgrade the fooman/tcpdf library to the patch version.