dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/readconvert.base64-encode/resource in the input_file parameter.
Publication date: Mon, 28 Apr 2014 19:09:00 +0000