Community
    • Login

    CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, CVE-2023-40166

    Scheduled Pinned Locked Moved Security
    security
    9 Posts 7 Posters 11.3k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • ScorpiusS Offline
      Scorpius
      last edited by

      Good day,

      Are there any feedback on the following CVEs?

      CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, CVE-2023-40166

      When can we expect a patched version to be released?

      gerdb42G Alan KilbornA 2 Replies Last reply Reply Quote 1
      • gerdb42G Offline
        gerdb42 @Scorpius
        last edited by

        This has already drawn some attention in the press. heise.de, a popular german IT-newssite mentions this quite prominently: https://www.heise.de/news/Entwickler-von-Notepad-ignoriert-offensichtlich-Sicherheitsluecken-9289124.html

        The original report can be found here: https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__/

        1 Reply Last reply Reply Quote 2
        • Alan KilbornA Offline
          Alan Kilborn @Scorpius
          last edited by

          @Scorpius said in CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, CVE-2023-40166:

          Are there any feedback on the following CVEs?

          Has this been made into a formal “issue” for Notepad++?
          Apparently the developer has been “contacted” but the official means (for tracking purposes, so the developer doesn’t lose sight of it) would be through an issue.

          rdipardoR PeterJonesP Sam JenkinsS 3 Replies Last reply Reply Quote 2
          • rdipardoR Offline
            rdipardo @Alan Kilborn
            last edited by rdipardo

            Has this been made into a formal “issue” for Notepad++?

            Just two private security notices and at least one private pull request, all in the past four months: https://securitylab.github.com/advisories/GHSL-2023-092_Notepad__

            1 Reply Last reply Reply Quote 0
            • PeterJonesP Offline
              PeterJones @Alan Kilborn
              last edited by

              @Alan-Kilborn ,

              Though today, months after the “private report”, someone finally bothered to make a public issue, after the public shaming and news articles were published. https://github.com/notepad-plus-plus/notepad-plus-plus/issues/14073

              Sam JenkinsS 1 Reply Last reply Reply Quote 0
              • Sam JenkinsS Offline
                Sam Jenkins @PeterJones
                last edited by

                @PeterJones It’s industry standard to report the issue to the maintainer directly, privately, to give them time to review and implement a fix before the security researchers make the information public.

                The security researchers reported this in April, have had responses from the developer, they have then waited four months (longer than a lot of other security researchers, I believe the Google security team give 90 days from initial contact).

                1 Reply Last reply Reply Quote 4
                • Sam JenkinsS Offline
                  Sam Jenkins @Alan Kilborn
                  last edited by Sam Jenkins

                  @Alan-Kilborn said in CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, CVE-2023-40166:

                  Apparently the developer has been “contacted” but the official means (for tracking purposes, so the developer doesn’t lose sight of it) would be through an issue.

                  GitHub has a built in mechanism for projects to have this tracked by the developers without making all the details public, which could potential help malicious actors to figure out how to create a virus/malware and start exploiting it.

                  1 Reply Last reply Reply Quote 6
                  • Mark OlsonM Offline
                    Mark Olson
                    last edited by

                    Just want to observe that it looks like fixes have finally made it into master:
                    https://github.com/notepad-plus-plus/notepad-plus-plus/commit/5402622abc1e0fd9477d3e4645240cc97791c081
                    https://github.com/notepad-plus-plus/notepad-plus-plus/commit/4b66d80b2f310fc3d6948c36ca44608b3b9a7a5d
                    https://github.com/notepad-plus-plus/notepad-plus-plus/commit/8c561ba74b35a48d102f9057ff20491f6be05ca7
                    https://github.com/notepad-plus-plus/notepad-plus-plus/commit/ea063246f16a73334ce84934152499c249e626f6

                    at least that appears to be the case based on my non-super-clear understanding of reading the securitylab.github.com advisory.

                    PeterJonesP 1 Reply Last reply Reply Quote 6
                    • PeterJonesP Offline
                      PeterJones @Mark Olson
                      last edited by

                      @Mark-Olson said in CVE-2023-40031, CVE-2023-40036, CVE-2023-40164, CVE-2023-40166:

                      Just want to observe that it looks like fixes have finally made it into master:

                      And into v8.5.7 RC, so the fixes will be in the next release in the very near future.

                      1 Reply Last reply Reply Quote 2

                      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                      With your input, this post could be even better 💗

                      Register Login
                      • First post
                        Last post
                      The Community of users of the Notepad++ text editor.
                      Powered by NodeBB | Contributors