CVE-2023-34194: High severity tinyxml vulnerability
Published Dec 13, 2023
·Updated
StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.
Affected Software
8 affected componentsFixes available
debian/tinyxml<=2.6.2-4
2.6.2-4+deb10u22.6.2-4+deb11u22.6.2-6+deb12u12.6.2-6.1
ubuntu/tinyxml<2.6.2-4ubuntu0.18.04.1~
2.6.2-4ubuntu0.18.04.1~
ubuntu/tinyxml<2.6.2-4+
2.6.2-4+
ubuntu/tinyxml<2.6.2-6ubuntu0.22.04.1
2.6.2-6ubuntu0.22.04.1
ubuntu/tinyxml<2.6.2-6ubuntu0.23.10.1
2.6.2-6ubuntu0.23.10.1
ubuntu/tinyxml<2.6.2-6.1
2.6.2-6.1
ubuntu/tinyxml<2.6.2-3ubuntu0.1~
2.6.2-3ubuntu0.1~
Tinyxml Project Tinyxml<=2.6.2
Remediation
Event History
Dec 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 30, 2024
Data Sourced
via Launchpad·10:52 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-34194?
CVE-2023-34194 is considered a security vulnerability that leads to a reachable assertion failure and application exit.
2
How do I fix CVE-2023-34194?
To fix CVE-2023-34194, upgrade TinyXML to a version above 2.6.2, such as 2.6.2-5 or later.
3
Which versions of TinyXML are affected by CVE-2023-34194?
CVE-2023-34194 affects all TinyXML versions up to and including 2.6.2.
4
What software is impacted by CVE-2023-34194?
CVE-2023-34194 impacts TinyXML versions through 2.6.2 across various Debian and Ubuntu packages.
5
Is there a specific patch for CVE-2023-34194?
There is no specific patch; users need to upgrade to the fixed version of TinyXML to mitigate CVE-2023-34194.