An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes.
Metrics
Affected Vendors & Products
References
History
Mon, 30 Dec 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-843 | |
Metrics |
cvssV3_1
|
Fri, 27 Dec 2024 04:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in TCPDF before 6.8.0. unserializeTCPDFtag uses != (aka loose comparison) and does not use a constant-time function to compare TCPDF tag hashes. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-12-27T00:00:00
Updated: 2024-12-30T15:54:30.643Z
Reserved: 2024-12-27T00:00:00
Link: CVE-2024-56522

Updated: 2024-12-30T15:48:35.679Z

Status : Awaiting Analysis
Published: 2024-12-27T05:15:08.130
Modified: 2024-12-30T16:15:11.920
Link: CVE-2024-56522

No data.