2025-03-14
ALT-BU-2025-4238-1
Branch c9f2 update bulletin.
Closed vulnerabilities
Published: 2021-09-14
BDU:2022-06895
Уязвимость функции TiXmlParsingData::Stamp компонента tinyxmlparser.cpp XML-парсера TinyXML, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2023-12-06
BDU:2024-00003
Уязвимость функции TiXmlDeclaration::Parse() компонента tinyxmlparser.cpp XML-парсера TinyXML, позволяющая нарушителю вызвать отказ в обслуживании
Severity: HIGH (7.5)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
Published: 2021-10-11
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2021-42260
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- [debian-lts-announce] 20220430 [SECURITY] [DLA 2988-1] tinyxml security update
- [debian-lts-announce] 20220430 [SECURITY] [DLA 2988-1] tinyxml security update
- [debian-lts-announce] 20220930 [SECURITY] [DLA 3130-1] tinyxml security update
- [debian-lts-announce] 20220930 [SECURITY] [DLA 3130-1] tinyxml security update
- FEDORA-2024-80e6578a01
- FEDORA-2024-80e6578a01
- FEDORA-2024-c9dc0ac419
- FEDORA-2024-c9dc0ac419
- https://sourceforge.net/p/tinyxml/bugs/141/
- https://sourceforge.net/p/tinyxml/bugs/141/
Published: 2023-12-13
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-34194
StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References:
- [debian-lts-announce] 20231230 [SECURITY] [DLA 3701-1] tinyxml security update
- FEDORA-2024-80e6578a01
- FEDORA-2024-c9dc0ac419
- https://sourceforge.net/p/tinyxml/git/ci/master/tree/tinyxmlparser.cpp
- https://www.forescout.com/resources/sierra21-vulnerabilities
- [debian-lts-announce] 20231230 [SECURITY] [DLA 3701-1] tinyxml security update
- https://www.forescout.com/resources/sierra21-vulnerabilities
- https://sourceforge.net/p/tinyxml/git/ci/master/tree/tinyxmlparser.cpp
- FEDORA-2024-c9dc0ac419
- FEDORA-2024-80e6578a01