Reachable assertion in tinyxml2 - CVE-2024-50615
Published: August 26, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in UINT_MAX/digit within the XMLUtil::GetCharacterRef() function in tinyxml2.cpp. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Affected software
openEuler
tinyxml2-devel
tinyxml2-debugsource
tinyxml2-debuginfo
tinyxml2
How to mitigate CVE-2024-50615
tinyxml2-devel - addressed in versions 6.0.0-6, 9.0.0-2
tinyxml2-debugsource - addressed in versions 6.0.0-6, 9.0.0-2
tinyxml2-debuginfo - addressed in versions 6.0.0-6, 9.0.0-2
tinyxml2 - addressed in versions 6.0.0-6, 9.0.0-2