Infinite loop in tinyxml - CVE-2021-42260
Published: December 8, 2023
Vulnerability identifier: #VU84001
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-42260
CWE-ID: CWE-835
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop within the TiXmlParsingData::Stamp() function in tinyxmlparser.cpp. A remote attacker can consume all available system resources and cause denial of service conditions.
Affected software
tinyxml
Fedora
Ubuntu
openEuler
libtinyxml-dev (Ubuntu package)
libtinyxml2.6.2v5 (Ubuntu package)
tinyxml-debuginfo
tinyxml-devel
tinyxml-debugsource
tinyxml
Kaspersky Security for Virtual Environments Light Agent for Windows (eng)
Kaspersky Security for Virtual Environments Light Agent for Windows (fr)
Kaspersky Security for Virtual Environments Light Agent for Windows (de)
Kaspersky Security for Virtual Environments Light Agent for Linux
Fedora
Ubuntu
openEuler
libtinyxml-dev (Ubuntu package)
libtinyxml2.6.2v5 (Ubuntu package)
tinyxml-debuginfo
tinyxml-devel
tinyxml-debugsource
tinyxml
Kaspersky Security for Virtual Environments Light Agent for Windows (eng)
Kaspersky Security for Virtual Environments Light Agent for Windows (fr)
Kaspersky Security for Virtual Environments Light Agent for Windows (de)
Kaspersky Security for Virtual Environments Light Agent for Linux
How to mitigate CVE-2021-42260
Install updates from vendor's website.
libtinyxml-dev (Ubuntu package) - addressed in versions Ubuntu Pro, 2.6.2-4+deb10u1build0.20.04.1
libtinyxml2.6.2v5 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.6.2-4+deb10u1build0.20.04.1
tinyxml-debuginfo - update to 2.6.2-22
tinyxml-devel - update to 2.6.2-22
tinyxml-debugsource - update to 2.6.2-22
tinyxml - update to 2.6.2-22
tinyxml - addressed in versions 2.6.2-28.el8, 2.6.2-28.el9, 2.6.2-28.fc38, 2.6.2-28.fc39, 2.6.2-28.fc40
Kaspersky Security for Virtual Environments Light Agent for Windows (eng) - update to 5.2 pf225
Kaspersky Security for Virtual Environments Light Agent for Windows (fr) - update to 5.2 pf226
Kaspersky Security for Virtual Environments Light Agent for Windows (de) - update to 5.2 pf227
Kaspersky Security for Virtual Environments Light Agent for Linux - update to 5.2.27-1843
libtinyxml2.6.2v5 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.6.2-4+deb10u1build0.20.04.1
tinyxml-debuginfo - update to 2.6.2-22
tinyxml-devel - update to 2.6.2-22
tinyxml-debugsource - update to 2.6.2-22
tinyxml - update to 2.6.2-22
tinyxml - addressed in versions 2.6.2-28.el8, 2.6.2-28.el9, 2.6.2-28.fc38, 2.6.2-28.fc39, 2.6.2-28.fc40
Kaspersky Security for Virtual Environments Light Agent for Windows (eng) - update to 5.2 pf225
Kaspersky Security for Virtual Environments Light Agent for Windows (fr) - update to 5.2 pf226
Kaspersky Security for Virtual Environments Light Agent for Windows (de) - update to 5.2 pf227
Kaspersky Security for Virtual Environments Light Agent for Linux - update to 5.2.27-1843
External References
Related Security Bulletins
- Denial of service in TinyXML
- Ubuntu update for tinyxml
- Fedora 40 update for tinyxml
- Fedora 39 update for tinyxml
- Fedora 38 update for tinyxml
- openEuler update for tinyxml
- Fedora EPEL 8 update for tinyxml
- Fedora EPEL 9 update for tinyxml
- Kaspersky Security for Virtual Environments Light Agent update for third-party components