Updated tinyxml packages fix a security vulnerability
Publication date: 17 Jan 2024Modification date: 17 Jan 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-34194
Description
The updated packages fix a security vulnerability: StringEqual in TiXmlDeclaration::Parse in tinyxmlparser.cpp in TinyXML through 2.6.2 has a reachable assertion (and application exit) via a crafted XML document with a '\0' located after whitespace. (CVE-2023-34194)
References
SRPMS
9/core
- tinyxml-2.6.2-14.1.mga9