There are 3 open security issues in bookworm.
3 issues left for the package maintainer to handle:
- CVE-2024-22640:
(needs triaging)
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
- CVE-2024-22641:
(needs triaging)
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.
- CVE-2024-32489:
(needs triaging)
TCPDF before 6.7.4 mishandles calls that use HTML syntax.
You can find information about how to handle these issues in the security team's documentation.