Reachable assertion in tinyxml2 - CVE-2024-50614

 

Reachable assertion in tinyxml2 - CVE-2024-50614

Published: August 26, 2025


Vulnerability identifier: #VU114425
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-50614
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a reachable assertion within the XMLUtil::GetCharacterRef() function in tinyxml2.cpp. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Affected software

tinyxml2
openEuler
Fedora
dvblinkremote
vdr-osd2web
xrootd-s3-http
rarian
openmw
docparser
vdr-epg2vdr
linbox
fuse-encfs
Macaulay2
cppcheck
linux-sgx
ags
bullet
lgogdownloader
urdfdom
musescore
tinyxml2-devel
tinyxml2-debugsource
tinyxml2-debuginfo
tinyxml2
gazebo
libmediainfo

How to mitigate CVE-2024-50614

Install updates from vendor's website.

tinyxml2 - update to 10.1.0
dvblinkremote - addressed in versions 0.2.0-0.37.beta.fc43, 0.2.0-0.37.beta.fc44
vdr-osd2web - addressed in versions 0.3.2-19.fc43, 0.3.2-19.fc44
xrootd-s3-http - addressed in versions 0.4.1-4.fc43, 0.4.1-4.fc44
rarian - addressed in versions 0.8.6-4.fc43, 0.8.6-4.fc44
openmw - addressed in versions 0.49.0-6.fc43, 0.49.0-6.fc44
docparser - addressed in versions 1.0.16-3.fc43, 1.0.16-3.fc44
vdr-epg2vdr - addressed in versions 1.2.17-8.fc43, 1.2.17-8.fc44
linbox - addressed in versions 1.7.1-2.fc43, 1.7.1-2.fc44
fuse-encfs - addressed in versions 1.9.5-26.fc43, 1.9.5-26.fc44
Macaulay2 - addressed in versions 1.25.06-3.fc43, 1.25.06-3.fc44
cppcheck - addressed in versions 2.18.1-2.fc43, 2.18.1-2.fc44
linux-sgx - addressed in versions 2.26-4.fc43, 2.26-4.fc44
ags - addressed in versions 3.6.2.12-4.fc43, 3.6.2.12-4.fc44
bullet - addressed in versions 3.08-15.fc43, 3.08-15.fc44
lgogdownloader - addressed in versions 3.16-5.fc43, 3.16-5.fc44
urdfdom - addressed in versions 4.0.2-2.fc43, 4.0.2-2.fc44
musescore - addressed in versions 4.3.2-21.fc43, 4.3.2-21.fc44
tinyxml2-devel - addressed in versions 6.0.0-6, 9.0.0-2
tinyxml2-debugsource - addressed in versions 6.0.0-6, 9.0.0-2
tinyxml2-debuginfo - addressed in versions 6.0.0-6, 9.0.0-2
tinyxml2 - addressed in versions 6.0.0-6, 9.0.0-2
gazebo - addressed in versions 10.2.0-15.fc43, 10.2.0-15.fc44
tinyxml2 - addressed in versions 11.0.0-1.fc43, 11.0.0-1.fc44
libmediainfo - addressed in versions 25.04-3.fc43, 25.04-3.fc44

External References

Related Security Bulletins