CVE-2018-17057
14.09.2018, 20:29
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.Enginsight
| Vendor | Product | Version |
|---|---|---|
| tecnick | tcpdf | 𝑥 < 6.2.22 |
| limesurvey | limesurvey | 𝑥 < 3.16.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References