CVE-2021-42260: High severity Tinyxml Project Tinyxml vulnerability
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXMLUTFLEAD0 case. It can be triggered by a crafted XML message and leads to a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tinyxmlto a version that resolves this vulnerability.Fixed in 2.6.2-4+deb10u2Fixed in 2.6.2-4+deb11u2Fixed in 2.6.2-6+deb12u1Fixed in 2.6.2-6.1 - Upgrade
Upgrade
ubuntu/tinyxmlto a version that resolves this vulnerability.Fixed in 2.6.2-4ubuntu0.18.04.1~ - Upgrade
Upgrade
ubuntu/tinyxmlto a version that resolves this vulnerability.Fixed in 2.6.2-4+ - Upgrade
Upgrade
ubuntu/tinyxmlto a version that resolves this vulnerability.Fixed in 2.6.2-3ubuntu0.1~
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42260?
CVE-2021-42260 has a high severity as it leads to a denial of service through an infinite loop.
How do I fix CVE-2021-42260?
To fix CVE-2021-42260, update your TinyXML package to versions 2.6.2-4+deb10u2, 2.6.2-4+deb11u2, or later.
What software is affected by CVE-2021-42260?
CVE-2021-42260 affects TinyXML versions up to and including 2.6.2.
What is the impact of CVE-2021-42260?
The impact of CVE-2021-42260 is denial of service caused by handling crafted XML messages.
Which distributions have packages affected by CVE-2021-42260?
Debian and Ubuntu distributions have vulnerable packages affected by CVE-2021-42260.