Описание
Security update for tinyxml
This update for tinyxml fixes the following issues:
- CVE-2023-34194: Fixed reachable assertion may lead to denial of service (bsc#1218040).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP5
libtinyxml0-2.6.2-150000.3.6.1
tinyxml-devel-2.6.2-150000.3.6.1
tinyxml-docs-2.6.2-150000.3.6.1
openSUSE Leap 15.4
libtinyxml0-2.6.2-150000.3.6.1
tinyxml-devel-2.6.2-150000.3.6.1
tinyxml-docs-2.6.2-150000.3.6.1
openSUSE Leap 15.5
libtinyxml0-2.6.2-150000.3.6.1
tinyxml-devel-2.6.2-150000.3.6.1
tinyxml-docs-2.6.2-150000.3.6.1
Ссылки
- Link for SUSE-SU-2023:4958-1
- E-Mail link for SUSE-SU-2023:4958-1
- SUSE Security Ratings
- SUSE Bug 1218040
- SUSE CVE CVE-2023-34194 page
Описание
StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP5:libtinyxml0-2.6.2-150000.3.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:tinyxml-devel-2.6.2-150000.3.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP5:tinyxml-docs-2.6.2-150000.3.6.1
openSUSE Leap 15.4:libtinyxml0-2.6.2-150000.3.6.1
Ссылки
- CVE-2023-34194
- SUSE Bug 1218040