Infinite loop in tinyxml - CVE-2021-42260

 

Infinite loop in tinyxml - CVE-2021-42260

Published: December 8, 2023


Vulnerability identifier: #VU84001
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-42260
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to infinite loop within the TiXmlParsingData::Stamp() function in tinyxmlparser.cpp. A remote attacker can consume all available system resources and cause denial of service conditions.


Affected software

tinyxml
Fedora
Ubuntu
openEuler
libtinyxml-dev (Ubuntu package)
libtinyxml2.6.2v5 (Ubuntu package)
tinyxml-debuginfo
tinyxml-devel
tinyxml-debugsource
tinyxml
Kaspersky Security for Virtual Environments Light Agent for Windows (eng)
Kaspersky Security for Virtual Environments Light Agent for Windows (fr)
Kaspersky Security for Virtual Environments Light Agent for Windows (de)
Kaspersky Security for Virtual Environments Light Agent for Linux

How to mitigate CVE-2021-42260

Install updates from vendor's website.

libtinyxml-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.6.2-4+deb10u1build0.20.04.1
libtinyxml2.6.2v5 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.6.2-4+deb10u1build0.20.04.1
tinyxml-debuginfo - update to 2.6.2-22
tinyxml-devel - update to 2.6.2-22
tinyxml-debugsource - update to 2.6.2-22
tinyxml - update to 2.6.2-22
tinyxml - addressed in versions 2.6.2-28.el8, 2.6.2-28.el9, 2.6.2-28.fc38, 2.6.2-28.fc39, 2.6.2-28.fc40
Kaspersky Security for Virtual Environments Light Agent for Windows (eng) - update to 5.2 pf225
Kaspersky Security for Virtual Environments Light Agent for Windows (fr) - update to 5.2 pf226
Kaspersky Security for Virtual Environments Light Agent for Windows (de) - update to 5.2 pf227
Kaspersky Security for Virtual Environments Light Agent for Linux - update to 5.2.27-1843

External References

Related Security Bulletins