---
title: "CVE-2023-23924\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2023-23924?format=md
keywords: index, follow
---

# CVE-2023-23924

Publication date 1 February 2023

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**9.8 · Critical**

[Score breakdown](https://ubuntu.com/security/CVE-2023-23924?format=md#impact-score)

Toggle side navigation

## Description

Dompdf is an HTML to PDF converter. The URI validation on dompdf 2.0.1 can
be bypassed on SVG parsing by passing `<image>` tags with uppercase
letters. This may lead to arbitrary object unserialize on PHP < 8, through
the `phar` URL wrapper. An attacker can exploit the vulnerability to call
arbitrary URL with arbitrary protocols, if they can provide a SVG file to
dompdf. In PHP versions before 8.0.0, it leads to arbitrary unserialize,
that will lead to the very least to an arbitrary file deletion and even
remote code execution, depending on classes that are available.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2023-23924?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| php-dompdf | 23.04 lunar | Not in release |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Ignored end of standard support |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2023-23924?format=md#patch-details)

## Notes

---

### [ccdm94](https://launchpad.net/~ccdm94)

according to upstream, this only affects version 2.0.1.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| php-dompdf | * Upstream:   [7558f07](https://github.com/dompdf/dompdf/commit/7558f07f693b2ac3266089f21051e6b78c6a0c85) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

9.8 · Critical

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 9.8 · Critical |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23924)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-23924)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-23924)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2023-23924)

### Other references

* <https://github.com/dompdf/dompdf/security/advisories/GHSA-3cw5-7cxw-v5qg>
* <https://github.com/dompdf/dompdf/releases/tag/v2.0.2>
* <https://github.com/dompdf/dompdf/commit/7558f07f693b2ac3266089f21051e6b78c6a0c85>
* <https://www.cve.org/CVERecord?id=CVE-2023-23924>
