CVE-2024-50615: Medium severity TinyXML TinyXML2 vulnerability
Published Oct 27, 2024
·Updated
TinyXML2 through 10.0.0 has a reachable assertion for UINTMAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
Affected Software
6 affected componentsFixes available
TinyXML TinyXML2<10.0.0
Tinyxml2 Project Tinyxml2<=10.0.0
Microsoft azl3 tinyxml2 9.0.0-2
Microsoft cbl2 tinyxml2 9.0.0-2
Microsoft cbl2 blobfuse 1.4.5-16
Microsoft cbl2 blobfuse 1.4.5-17
Event History
Oct 27, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
May 5, 2025
Data Sourced
via Microsoft·12:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·12:00 AM
SeverityAffected Software
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Updated
via Microsoft·07:00 AM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-50615?
CVE-2024-50615 is classified as a critical vulnerability due to the potential for application exit.
2
How does CVE-2024-50615 affect TinyXML2 users?
Users of TinyXML2 version 10.0.0 and earlier may encounter an assertion failure that could lead to unexpected application termination.
3
What versions of TinyXML2 are affected by CVE-2024-50615?
CVE-2024-50615 affects TinyXML2 versions up to and including 10.0.0.
4
How can developers mitigate CVE-2024-50615?
To mitigate CVE-2024-50615, developers should upgrade TinyXML2 to a version newer than 10.0.0.
5
Is there a patch available for CVE-2024-50615?
Yes, users should check the latest releases of TinyXML2 for any patches addressing CVE-2024-50615.