CVE-2021-42260
Summary
| CVE | CVE-2021-42260 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-11 20:15:00 UTC |
| Updated | 2024-01-12 03:15:00 UTC |
| Description | TinyXML through 2.6.2 has an infinite loop in TiXmlParsingData::Stamp in tinyxmlparser.cpp via the TIXML_UTF_LEAD_0 case. It can be triggered by a crafted XML message and leads to a denial of service. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179254 Debian Security Update for tinyxml (DLA 2988-1)
- 181089 Debian Security Update for tinyxml (DLA 3130-1)
- 181348 Debian Security Update for tinyxml (CVE-2021-42260)
- 199989 Ubuntu Security Notification for TinyXML Vulnerability (USN-6542-1)
- 284854 Fedora Security Update for tinyxml (FEDORA-2024-c9dc0ac419)
- 285065 Fedora Security Update for tinyxml (FEDORA-2024-80e6578a01)
- 751341 OpenSUSE Security Update for tinyxml (openSUSE-SU-2021:3639-1)
- 751351 OpenSUSE Security Update for tinyxml (openSUSE-SU-2021:1474-1)