title: Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
link: https://github.com/tecnickcom/TCPDF/commit/1861e33fe05f653b67d070f7c106463e7a5c26ed
cve: CVE-2018-17057
branches:
master:
time: 2018-09-20 05:24:43
versions: ['<6.2.22']
reference: composer://fooman/tcpdf