View Issue Details

This bug affects 1 person(s).
 250
IDProjectCategoryView StatusLast Update
14824Bug reportsSecuritypublic2019-04-30 09:22
Reporterbewi Assigned Toc_schmitz  
PrioritynoneSeverityminor 
Status closedResolutionduplicate 
Product Version3.17.x 
Fixed in Version3.17.x 
Summary14824: old version of TCPDF
Description

An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

https://www.cvedetails.com/cve/CVE-2018-17057/

TagsNo tags attached.
Bug heat250
Complete LimeSurvey version number (& build)Version 3.17.1+190408
I will donate to the project if issue is resolvedNo
Browser
Database type & version*
Server OS (if known)
Webserver software & version (if known)
PHP Version*

Relationships

duplicate of 14670 closedDenisChenu Remote Code Execution in Limesurvey <= 3.16.x via Deserialization Attack in "tcpdf" 

Users monitoring this issue

There are no users monitoring this issue.

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2019-04-30 08:55 bewi New Issue
2019-04-30 09:22 c_schmitz Relationship added duplicate of 14670
2019-04-30 09:22 c_schmitz Assigned To => c_schmitz
2019-04-30 09:22 c_schmitz Status new => closed
2019-04-30 09:22 c_schmitz Resolution open => duplicate
2019-04-30 09:22 c_schmitz Fixed in Version => 3.17.x