Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
197

Debian 11: DLA-4199-1 critical: tcpdf denial of service issues

Multiple security issues were discovered in TCPDF, a PHP class for generating PDF files on-the-fly, which may result in denial of service, cross-site scripting or information disclosure. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4199-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Santiago Ruano Rincón May 31, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : tcpdf Version : 6.3.5+dfsg1-1+deb11u1 CVE ID : CVE-2024-22640 CVE-2024-22641 CVE-2024-32489 CVE-2024-51058 CVE-2024-56519 CVE-2024-56520 CVE-2024-56522 CVE-2024-56527 Multiple security issues were discovered in TCPDF, a PHP class for generating PDF files on-the-fly, which may result in denial of service, cross-site scripting or information disclosure. CVE-2024-22640 ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color. CVE-2024-22641 ReDoS (Regular Expression Denial of Service) when parsing a specially crafted SVG file. CVE-2024-32489 TCPDF mishandles calls that use HTML syntax. CVE-2024-51058 Local File Inclusion (LFI) vulnerability through the src tag. CVE-2024-56519 setSVGStyles does not sanitize the SVG font-family attribute. CVE-2024-56520 TCPDF, throught its use of tc-lib-pdf-font, mishandles fonts like FontBBox for Type 1 and misparses TrueType fonts. CVE-2024-56522 The unserializeTCPDFtag() function doesn't make use of constant-time function to compare TCPDF tag hashes. CVE-2024-56527 The Error() function lacks an htmlspecialchars call for the error message. For Debian 11 bullseye, these problems have been fixed in version 6.3.5+dfsg1-1+deb11u1. We recommend that you upgrade your tcpdf packages. For the detailed security status oftcpdf please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/tcpdf Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . This patch resolves multiple vulnerabilities in TCPDF for Debian systems, protecting against denial of service attacks and other potential risks.. tcpdf security, Debian advisory, security update, PDF generation vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 03, 2025 Critical Debian LTS
87

Debian: DSA-5933-1 high: tcpdf denial of service and XSS

Multiple security issues were discovered in TCPDF, a PHP class for generating PDF files on-the-fly, which may result in denial of service, cross-site scripting or information disclosure. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5933-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 01, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tcpdf CVE ID : CVE-2024-22640 CVE-2024-22641 CVE-2024-32489 CVE-2024-51058 CVE-2024-56519 CVE-2024-56520 CVE-2024-56522 CVE-2024-56527 Multiple security issues were discovered in TCPDF, a PHP class for generating PDF files on-the-fly, which may result in denial of service, cross-site scripting or information disclosure. For the stable distribution (bookworm), these problems have been fixed in version 6.6.2+dfsg1-1+deb12u1. We recommend that you upgrade your tcpdf packages. For the detailed security status of tcpdf please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/tcpdf Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover significant TCPDF vulnerabilities, including DoS and XSS threats, along with update instructions tailored for Debian users.. TCPDF Security, Denial Of Service, Cross-Site Scripting, PHP Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 01, 2025 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here