UBUNTU-CVE-2018-11210

Source
https://ubuntu.com/security/CVE-2018-11210
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-11210.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2018-11210
Upstream
Withdrawn
2025-07-08T10:45:29Z
Published
2018-05-16T15:29:00Z
Modified
2025-07-08T14:59:39.120503Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
  • - medium
Summary
[none]
Details

* DISPUTED * TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2.

References

Affected packages

Ubuntu:Pro:14.04:LTS / tinyxml2

Package

Name
tinyxml2
Purl
pkg:deb/ubuntu/tinyxml2@0~git20120518.1.a2ae54e-1?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0~git20120518.*
0~git20120518.1.a2ae54e-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-11210.json"

Ubuntu:Pro:16.04:LTS / tinyxml2

Package

Name
tinyxml2
Purl
pkg:deb/ubuntu/tinyxml2@2.2.0-1.1ubuntu1?arch=source&distro=esm-apps/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.0-1.1ubuntu1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-11210.json"

Ubuntu:Pro:18.04:LTS / tinyxml2

Package

Name
tinyxml2
Purl
pkg:deb/ubuntu/tinyxml2@6.0.0+dfsg-1?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.0.1-1
6.*
6.0.0+dfsg-1

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2018/UBUNTU-CVE-2018-11210.json"