CVE-2024-56520

HIGH7.3EPSS 0.09%

tecnickcom/tc-lib-pdf-font mishandles fonts

Published: 12/27/2024Modified: 11/4/2025
Also known as:GHSA-grhh-r4jj-8jh7

Description

An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mishandled, e.g., FontBBox for Type 1 and TrueType fonts is misparsed.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References (9)