• Login
Community
  • Login

CVEs in Notepad++ V8.5.6 and Prior

Scheduled Pinned Locked Moved General Discussion
2 Posts 2 Posters 768 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M
    Murray Sobol 1
    last edited by Sep 7, 2023, 4:19 PM

    The following CVEs have been reported in Notepad++ V8.5.6 and Prior
    CVE-2023-40166
    Versions 8.5.6 and prior are vulnerable to heap buffer read overflow in FileManager::detectLanguageFromTextBegining . The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information.
    CVE-2023-40164
    Versions 8.5.6 and prior are vulnerable to global buffer read overflow in nsCodingStateMachine::NextStater. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information.
    CVE-2023-40036
    Versions 8.5.6 and prior are vulnerable to global buffer read overflow in CharDistributionAnalysis::HandleOneChar. The exploitability of this issue is not clear. Potentially, it may be used to leak internal memory allocation information.
    CVE-2023-40031
    Versions 8.5.6 and prior are vulnerable to heap buffer write overflow in Utf8_16_Read::convert. This issue may lead to arbitrary code execution.

    For all of the above CVEs, As of time of publication, no known patches are available in existing versions of Notepad++.

    I sincerely hope that these issues are being addressed and will be resolved in a not to distant version of Notepad++.

    P 1 Reply Last reply Sep 7, 2023, 4:24 PM Reply Quote -3
    • P
      PeterJones @Murray Sobol 1
      last edited by PeterJones Sep 7, 2023, 4:28 PM Sep 7, 2023, 4:24 PM

      @Murray-Sobol-1 said in CVEs in Notepad++ V8.5.6 and Prior:

      The following CVEs have been reported in Notepad++ V8.5.6 and Prior

      Already addressed:
      https://community.notepad-plus-plus.org/topic/24889/notepad-v8-5-7-release-candidate

      For all of the above CVEs, As of time of publication, no known patches are available in existing versions of Notepad++.

      Notepad++ does not do “patch” releases. It just releases new versions. And the new version implementing the fixes is available in release-candidate, and will be switched to full release soon,

      1 Reply Last reply Reply Quote 2
      1 out of 2
      • First post
        1/2
        Last post
      The Community of users of the Notepad++ text editor.
      Powered by NodeBB | Contributors