CVE Identifier: CVE-2024-56520 Description: Mishandling of fonts in before version 2.6.4, affecting TCPDF before 6.8.0 and other products. FontBBox for Type 1 and TrueType fonts is misparsed. Affected Versions: All versions before 2.6.4 Fixed Versions: 2.6.4 Solution: Upgrade to version 2.6.4 or above. Impact: High severity, CVSS score of 7.3 Source File: Packagist/tecnickcom/tc-lib-pdf-font/CVE... References: - GitHub Advisory - GitHub Commit Changes - GitHub Compare Changes - tc-lib-pdf-font GitHub Page - Commit for tc-lib-pdf-font Change - Comparisons for tc-lib-pdf-font Versions - Debian LTS Announcement - NVD NIST Details - TCPDF Website