Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-34194
HistoryDec 13, 2023 - 12:00 a.m.

CVE-2023-34194

2023-12-1300:00:00
ubuntu.com
ubuntu.com
17
cve-2023-34194
tinyxml
xml
assertion
reachable
crafted document
vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

20.3%

StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML
through 2.6.2 has a reachable assertion (and application exit) via a
crafted XML document with a ‘\0’ located after whitespace.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchtinyxml< 2.6.2-4ubuntu0.18.04.1~esm2UNKNOWN
ubuntu20.04noarchtinyxml< 2.6.2-4+deb10u2build0.20.04.1UNKNOWN
ubuntu22.04noarchtinyxml< 2.6.2-6ubuntu0.22.04.1UNKNOWN
ubuntu23.10noarchtinyxml< 2.6.2-6ubuntu0.23.10.1UNKNOWN
ubuntu16.04noarchtinyxml< 2.6.2-3ubuntu0.1~esm2UNKNOWN

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

20.3%