MGASA-2024-0014

Source
https://advisories.mageia.org/MGASA-2024-0014.html
Import Source
https://advisories.mageia.org/MGASA-2024-0014.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2024-0014
Related
Published
2024-01-17T23:50:39Z
Modified
2024-01-17T23:12:36Z
Summary
Updated tinyxml packages fix a security vulnerability
Details

The updated packages fix a security vulnerability: StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace. (CVE-2023-34194)

References
Credits

Affected packages

Mageia:9 / tinyxml

Package

Name
tinyxml
Purl
pkg:rpm/mageia/tinyxml?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.2-14.1.mga9

Ecosystem specific

{
    "section": "core"
}