跳转到帖子

Debian: CVE-2021-3838: php-dompdf -- security update

recommended_posts

发布于
  • Members

Debian: CVE-2021-3838: php-dompdf -- security update

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
07/17/2023
Created
07/17/2023
Added
07/17/2023
Modified
01/28/2025

Description

DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code.

Solution(s)

  • debian-upgrade-php-dompdf

References

  • https://attackerkb.com/topics/cve-2021-3838
  • CVE - 2021-3838
  • DLA-3495-1
  • 查看数 701
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…