An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
Metrics
Affected Vendors & Products
References
History
Thu, 17 Apr 2025 02:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Tcpdf Project
Tcpdf Project tcpdf |
|
CPEs | cpe:2.3:a:tcpdf_project:tcpdf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Tcpdf Project
Tcpdf Project tcpdf |
Mon, 30 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-843 | |
Metrics |
cvssV3_1
|
Fri, 27 Dec 2024 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-30T15:54:30.643Z
Reserved: 2024-12-27T00:00:00
Link: CVE-2024-56522

Updated: 2024-12-30T15:48:35.679Z

Status : Analyzed
Published: 2024-12-27T05:15:08.130
Modified: 2025-04-17T02:12:05.617
Link: CVE-2024-56522

No data.