Ubuntu CVE Tracker
Home
Main
Universe
Partner
CVE-2021-42260
Priority
Medium
Description
TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in
tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a
crafted XML message and leads to a denial of service.
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42260
https://sourceforge.net/p/tinyxml/bugs/141/
Assigned-to
pfsmorigo
Notes
Package
Source:
tinyxml
(
LP
Ubuntu
Debian
)
Upstream:
needs-triage
Ubuntu 18.04 LTS
:
needed
Ubuntu 20.04 LTS
:
needed
Ubuntu 21.10
:
needed
Ubuntu 16.04 ESM:
needs-triage
Ubuntu 22.04 LTS
:
needs-triage
Patches:
More Information
Mitre
NVD
Launchpad
Debian
Updated
: 2022-04-25 00:58:57 UTC (commit
ecc1009cb19540b950de59270950018900f37f15
)