CVE-2018-17057
14.09.2018, 20:29
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.Enginsight
Vendor | Product | Version |
---|---|---|
tecnick | tcpdf | 𝑥 < 6.2.22 |
limesurvey | limesurvey | 𝑥 < 3.16.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References