Publishing details

Changelog

tinyxml (2.6.2-4+deb10u2build0.20.04.1) focal-security; urgency=medium

  * fake sync from Debian

tinyxml (2.6.2-4+deb10u2) buster-security; urgency=high

  * Non-maintainer upload by the LTS Security Team.
  * Fix CVE-2023-34194 / CVE-2023-40462: Reachable assertion (and application
    exit) via a crafted XML document with a '\0' located after whitespace.
    (Closes: #1059315)

 -- Giampaolo Fresi Roglia <email address hidden>  Mon, 29 Jan 2024 14:08:54 +0100

Available diffs

Builds

Built packages

Package files