Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora 39: 2024-80e6578a01 Critical: tinyxml DoS Issues Fixed

fedora
Calendar Grey January 8, 2024
Dist Fedora Esm H88
The recent Fedora patch upgrade bolsters TinyXML by integrating essential security enhancements, thereby increasing the software's stability and improving its encoding capabilities.
Bugfix release

Summary

TinyXML is a simple, small, C++ XML parser that can be easily integrating

into other programs. Have you ever found yourself writing a text file parser

every time you needed to save human readable data or serialize objects?

TinyXML solves the text I/O file once and for all.

(Or, as a friend said, ends the Just Another Text File Parser problem.)

Update Information:

Bugfix release. Includes security fixes for CVE-2021-42260 and CVE-2023-34194 and a fix for incorrect text element encoding (upstream isssue #51).

Change Log

* Wed Jan 3 2024 Dominik Mierzejewski - 2.6.2-28 - apply Debian patch to fix CVE-2021-42260 (rhbz#2253716, rhbz#2253718) - apply Debian patch to fix CVE-2023-34194 and its duplicate, CVE-2023-40462 (rhbz#2254376, rhbz#2254381) - fix incorrect text element encoding (upstream isssue #51) - compile and run tests

References


[ 1 ] Bug #2253716 - CVE-2021-42260 tinyxml: infinite loop causes crash https://bugzilla.redhat.com/show_bug.cgi?id=2253716 [ 2 ] Bug #2254376 - CVE-2023-34194 tinyxml: reachable assertion may lead to denial of service https://bugzilla.redhat.com/show_bug.cgi?id=2254376

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-80e6578a01' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: tinyxml
Product: Fedora 39
Version: 2.6.2
Release: 28.fc39
URL: Summary : A simple, small, C++ XML parser

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here