Notepad++ release 8.9.8
-
Notepad++ release 8.9.8 is available:
https://notepad-plus-plus.org/news/v898-released/
Notepad++ v8.9.8 vulnerability fix, bug-fixes & new features:
- Vulnerabilty: Fix an eventual crash while loading UDL. CVE ID not assigned yet
- Vulnerabilty: Fix an eventual crash when loading a UTF-16 file. CVE ID not assigned yet
- Vulnerabilty: Fix out-of-bounds array write. CVE ID not assigned yet
- Vulnerabilty: Fix authenticode verification bypass. CVE ID not assigned yet
- Vulnerabilty: Fix a TOCTOU issue in the Notepad++ Updater (WinGUp). CVE ID not assigned yet
- Vulnerabilty: Fix session backup path-traversal allowing deletiion outside backup directory. CVE ID not assigned yet
- Vulnerabilty: Fix potential exposure of Windows login info (SMB/NTLM) via UNC path. CVE ID not assigned yet 1, CVE ID not assigned yet 2, CVE ID not assigned yet 3, CVE ID not assigned yet 4
- Vulnerabilty: Fix shortcuts.xml HMAC bypass via the “Run a Macro Multiple Times”. CVE ID not assigned yet
- Vulnerabilty: Fix Null pointer in NPPM_SAVESESSION handler causing crash. CVE ID not assigned yet
- Vulnerabilty: Fix stack buffer overflow caused by overlong session paths. CVE ID not assigned yet
- Vulnerabilty: Fix Folder as Workspace “Run by system” target hijacking issue. CVE ID not assigned yet
- Vulnerabilty: Fix install-path injection possibility with PowerShell. CVE ID not assigned yet
- Vulnerabilty: Fix lower IL (Integrity Level) process sends WM_COMMAND to higher IL Notepad++. CVE ID not assigned yet
- Vulnerabilty: Fix Notepad++ UIPI Bypass via WM_COPYDATA. CVE ID not assigned yet
- Fix crash in WM_COPYDATA COPYDATA_PARAMS for invalid payload. (Fix #18207)
- Fix crash in API NPPM_ALLOCATE* calls. (Fix #18222)
- Add an option to allow loading symlinks in Folder as Workspace. (Fix #18226)
- Regression: Fix loading session for alone subview and doc/tab with untitle name. (Fix #18294)
- Fix CJK IME issues in Save As dialog. (Fix #11582, #15431, #16772, #12225, #12366)
- Update to Scintilla 5.6.6 & Lexilla 5.5.3. (Implement #18290)
- Add plugin deactivation capability. (Fix #18206)
- Add “-monitoringMode” command line argument to open files with monitoring enabled. (Fix #18188)
- Fix Proxy Settings issue in portable mode. (Fix #13382)
- Fix langs.xml model update not not applying file extension fields. (Fix #18220)
- Fix luminosity slider in ChooseColor not visible in dark mode. (Fix #12451)
- Fix empty sub-menus in compact language menu. (Fix #18202)
- Fix Search Results vertical scrolling not matching with OS mouse settings. (Implement #18194)
- Use modern question mark icon in dark message box. (Fix Repported in comment)
- Format count numbers using current locale separators when needed. (Fix #18190)
Auto-updater will be triggered in about 1 week, if no critical issue found in this release.
-
A serious regression: #18314
For that one, I have a simple fix ready and users already confirmed that it works ok.There is also unconfirmed #18315, for which the user also stated that reverting to the previous v8.9.7 helps. But IDK what to think about that one, I cannot reproduce and from its description I don’t really get what could be going on there, can you take a look at it?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login