CVE-2024-50614: Medium severity TinyXML TinyXML2 vulnerability
Published Oct 27, 2024
·Updated
TinyXML2 through 10.0.0 has a reachable assertion for UINTMAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
Affected Software
6 affected componentsFixes available
TinyXML TinyXML2<=10.0.0
Tinyxml2 Project Tinyxml2<=10.0.0
Microsoft cbl2 tinyxml2 9.0.0-2
Microsoft cbl2 blobfuse 1.4.5-17
Microsoft azl3 tinyxml2 9.0.0-2
Microsoft cbl2 blobfuse 1.4.5-16
Event History
Oct 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 3, 2025
Data Sourced
via Microsoft·09:15 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·09:15 PM
SeverityAffected Software
Sep 4, 2025
Updated
via Microsoft·04:15 AM
SeverityAffected Software
Updated
via Microsoft·04:15 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-50614?
CVE-2024-50614 has a severity rating that indicates it can lead to application exit due to a reachable assertion.
2
How do I fix CVE-2024-50614?
To fix CVE-2024-50614, update TinyXML2 to a version higher than 10.0.0 that addresses this vulnerability.
3
What versions of TinyXML2 are affected by CVE-2024-50614?
CVE-2024-50614 affects TinyXML2 versions up to and including 10.0.0.
4
What is the potential impact of CVE-2024-50614?
The potential impact of CVE-2024-50614 is the unexpected exit of applications using TinyXML2.
5
Where can I find more information about CVE-2024-50614?
More information about CVE-2024-50614 can typically be found in the official TinyXML2 issue tracker or security advisories.