USN-6612-1: TinyXML vulnerability
Published Jan 29, 2024
·Updated
It was discovered that TinyXML incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted XML file, a remote attacker could possibly use this issue to cause a denial of service.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/libtinyxml2.6.2v5<2.6.2-6ubuntu0.23.10.1
2.6.2-6ubuntu0.23.10.1
Ubuntu Ubuntu=23.10
All of the following
ubuntu/libtinyxml2.6.2v5<2.6.2-6ubuntu0.22.04.1
2.6.2-6ubuntu0.22.04.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libtinyxml2.6.2v5<2.6.2-4+deb10u2build0.20.04.1
2.6.2-4+deb10u2build0.20.04.1
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libtinyxml2.6.2v5<2.6.2-4ubuntu0.18.04.1~esm2
2.6.2-4ubuntu0.18.04.1~esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libtinyxml2.6.2v5<2.6.2-3ubuntu0.1~esm2
2.6.2-3ubuntu0.1~esm2
Ubuntu Ubuntu=16.04
Event History
Jan 29, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-6612-1?
USN-6612-1 is classified as a vulnerability that could lead to denial of service under certain circumstances.
2
How do I fix USN-6612-1?
To fix USN-6612-1, upgrade the affected package libtinyxml2.6.2v5 to a safe version as specified in the advisory.
3
Which versions of Ubuntu are affected by USN-6612-1?
Ubuntu versions 16.04, 18.04, 20.04, 22.04, and 23.10 are affected by USN-6612-1.
4
What is the cause of the vulnerability in USN-6612-1?
The vulnerability in USN-6612-1 is due to TinyXML incorrectly handling certain specially crafted XML inputs.
5
Could USN-6612-1 allow remote code execution?
USN-6612-1 does not allow remote code execution, but it can cause a denial of service.