Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

openSUSE 15.5 Security Advisory 2023:4958-1 Moderate: tinyxml DoS

opensuse
Calendar Grey December 22, 2023
Dist Opensuse Esm H88
Upgrade for tinyxml tackling CVE-2023-34194 rated as moderate. Make sure your openSUSE installations are protected and current.
This update for tinyxml fixes the following issues: CVE-2023-34194: Fixed reachable assertion may lead to denial of service (bsc#1218040).

Description

This update for tinyxml fixes the following issues:

* CVE-2023-34194: Fixed reachable assertion may lead to denial of service

(bsc#1218040).

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* openSUSE Leap 15.5

zypper in -t patch openSUSE-SLE-15.5-2023-4958=1

* SUSE Package Hub 15 15-SP5

zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-4958=1

* openSUSE Leap 15.4

zypper in -t patch openSUSE-SLE-15.4-2023-4958=1

Package List

* openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64)

* libtinyxml0-2.6.2-150000.3.6.1

* libtinyxml0-debuginfo-2.6.2-150000.3.6.1

* tinyxml-devel-2.6.2-150000.3.6.1

* tinyxml-debugsource-2.6.2-150000.3.6.1

* tinyxml-docs-2.6.2-150000.3.6.1

* SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64)

* libtinyxml0-2.6.2-150000.3.6.1

* libtinyxml0-debuginfo-2.6.2-150000.3.6.1

* tinyxml-devel-2.6.2-150000.3.6.1

* tinyxml-debugsource-2.6.2-150000.3.6.1

* tinyxml-docs-2.6.2-150000.3.6.1

* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64)

* libtinyxml0-2.6.2-150000.3.6.1

* libtinyxml0-debuginfo-2.6.2-150000.3.6.1

* tinyxml-devel-2.6.2-150000.3.6.1

* tinyxml-debugsource-2.6.2-150000.3.6.1

* tinyxml-docs-2.6.2-150000.3.6.1

References

* bsc#1218040

## References:

* https://www.suse.com/security/cve/CVE-2023-34194.html

* https://bugzilla.suse.com/show_bug.cgi?id=1218040

Announcement ID: SUSE-SU-2023:4958-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here