Home

Description

An issue was discovered in tc-lib-pdf-font before 2.6.4, as used in TCPDF before 6.8.0 and other products. Fonts are mishandled, e.g., FontBBox for Type 1 and TrueType fonts is misparsed.

PUBLISHED Reserved 2024-12-27 | Published 2024-12-27 | Updated 2025-11-03 | Assigner mitre

Product status

Default status
unaffected

Any version before 6.8.0
affected

References

lists.debian.org/debian-lts-announce/2025/06/msg00004.html

tcpdf.org

github.com/tecnickcom/TCPDF/compare/6.7.8...6.8.0

github.com/...ommit/a0a02efe487cc39bd5223359e916dbeafb5cd6fe

github.com/...ommit/30012e333ae611c514ec2dc7cb370bbf4da4e677

github.com/tecnickcom/tc-lib-pdf-font/compare/2.6.2...2.6.4

cve.org (CVE-2024-56520)

nvd.nist.gov (CVE-2024-56520)

Download JSON