There are 4 open security issues in bookworm.
1 important issue:
- CVE-2024-51058:
Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information.
3 issues left for the package maintainer to handle:
- CVE-2024-22640:
(needs triaging)
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
- CVE-2024-22641:
(needs triaging)
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.
- CVE-2024-32489:
(needs triaging)
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
You can find information about how to handle these issues in the security team's documentation.