Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-34194

Опубликовано: 13 дек. 2023
Источник: debian
EPSS Низкий

Описание

StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tinyxmlfixed2.6.2-6.1package
tinyxmlfixed2.6.2-6+deb12u1bookwormpackage
tinyxmlfixed2.6.2-4+deb11u2bullseyepackage

Примечания

  • https://www.forescout.com/resources/sierra21-vulnerabilities

  • Debian (non upstream) patch: https://salsa.debian.org/debian/tinyxml/-/raw/2366e1f23d059d4c20c43c54176b6bd78d6a83fc/debian/patches/CVE-2023-34194.patch

EPSS

Процентиль: 76%
0.00952
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.

CVSS3: 7.5
nvd
почти 2 года назад

StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.

suse-cvrf
почти 2 года назад

Security update for tinyxml

CVSS3: 7.5
github
почти 2 года назад

StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость функции TiXmlDeclaration::Parse() компонента tinyxmlparser.cpp XML-парсера TinyXML, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 76%
0.00952
Низкий