registerFont in FontMetrics.php in Dompdf before 2.0.1 allows remote file inclusion because a URI validation failure does not halt font registration, as demonstrated by a @font-face rule.
References
Link Resource
https://github.com/dompdf/dompdf/issues/2994 Exploit Issue Tracking Patch Third Party Advisory
https://github.com/dompdf/dompdf/pull/2995 Patch Third Party Advisory
https://github.com/dompdf/dompdf/releases/tag/v2.0.1 Release Notes Third Party Advisory
https://tantosec.com/blog/cve-2022-41343/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-25T00:00:00

Updated: 2022-10-07T00:00:00

Reserved: 2022-09-25T00:00:00


Link: CVE-2022-41343

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-09-25T19:15:09.763

Modified: 2022-11-21T19:28:10.920


Link: CVE-2022-41343

JSON object: View

cve-icon Redhat Information

No data.

CWE