[Git][security-tracker-team/security-tracker][master] Add CVE-2024-32489/tcpdf

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Apr 15 18:14:06 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c3e8975d by Salvatore Bonaccorso at 2024-04-15T19:13:38+02:00
Add CVE-2024-32489/tcpdf

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -43,7 +43,9 @@ CVE-2024-3701 (The system application (com.transsion.kolun.aiservice) component
 CVE-2024-3505 (JFrog Artifactory Self-Hosted versions below 7.77.3, are vulnerable to ...)
 	NOT-FOR-US: JFrog Artifactory Self-Hosted
 CVE-2024-32489 (TCPDF before 6.7.4 mishandles calls that use HTML syntax.)
-	TODO: check
+	- tcpdf 6.7.4+dfsg-1
+	NOTE: Fixed by: https://github.com/tecnickcom/TCPDF/commit/51cd1b39de5643836e62661d162c472d63167df7
+	NOTE: Fixed by: https://github.com/tecnickcom/TCPDF/commit/82fc97bf1c74c8dbe62b1d3cc6d10fa4b87e0262 (6.7.4)
 CVE-2024-32488 (In Foxit PDF Reader and Editor before 2024.1, Local Privilege Escalati ...)
 	NOT-FOR-US: Foxit
 CVE-2024-32454 (Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appoi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3e8975df7b5f7258995b3216f33e436bcd84470

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c3e8975df7b5f7258995b3216f33e436bcd84470
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240415/9ad2a8aa/attachment.htm>


More information about the debian-security-tracker-commits mailing list