7.5
CVSSv3

CVE-2023-34194

Published: 13/12/2023 Updated: 12/01/2024
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML up to and including 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace.

Vulnerable Product Search on Vulmon Subscribe to Product

tinyxml project tinyxml

Vendor Advisories

Debian Bug report logs - #1059315 tinyxml: CVE-2023-34194 CVE-2023-40462 CVE-2023-40458 Package: src:tinyxml; Maintainer for src:tinyxml is Felix Geyer <fgeyer@debianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 22 Dec 2023 13:54:02 UTC Severity: important Tags: security, upstream Reply or ...