Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 568
Alerts This Week
Warning Icon 1 568

Ubuntu 23.10 USN-6612-1 Critical: TinyXML Denial Of Service Advisory

ubuntu
Calendar Grey January 30, 2024
Scroller Ubuntu
Incompatibilities in TinyXML may lead to program failures when attempting to access specific data files. Guidance for updates and potential effects are thoroughly outlined.
TinyXML could be made to crash if it opened a specially crafted file.

Summary

TinyXML could be made to crash if it opened a specially crafted file.

Software Description:

- tinyxml: A simple, small, minimal, C++ XML parser

Details:

It was discovered that TinyXML incorrectly handled certain inputs. If a

user or an automated system were tricked into opening a specially crafted

XML file, a remote attacker could possibly use this issue to cause a

denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 23.10:
  libtinyxml2.6.2v5               2.6.2-6ubuntu0.23.10.1

Ubuntu 22.04 LTS:
  libtinyxml2.6.2v5               2.6.2-6ubuntu0.22.04.1

Ubuntu 20.04 LTS:
  libtinyxml2.6.2v5               2.6.2-4+deb10u2build0.20.04.1

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
  libtinyxml2.6.2v5               2.6.2-4ubuntu0.18.04.1~esm2

Ubuntu 16.04 LTS (Available with Ubuntu Pro):
  libtinyxml2.6.2v5               2.6.2-3ubuntu0.1~esm2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6612-1

CVE-2023-34194

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6612-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.