Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Sun, 19 Feb 2017 17:43:59 +0100
From: Salvatore Bonaccorso <carnil@...ian.org>
To: OSS Security Mailinglist <oss-security@...ts.openwall.com>
Subject: TCPDF: CVE-2017-6100: LFI posting internal files externally abusing
 default parameter

Hi

CVE-2017-6100 has been assigned for the following issue in TCPDF:

https://sourceforge.net/p/tcpdf/bugs/1005/

tcpdf allows to upload files from the server generating PDF-files to
an external FTP.

The issue was discovered by  Frans Rosén.

Regards,
Salvatore

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.