vendor:
Notepad++
by:
sajith
5.5
CVSS
MEDIUM
DOS
119
CWE
Product Name: Notepad++
Affected Version From: DSpellCheck v1.2.12.0
Affected Version To: DSpellCheck v1.2.12.0
Patch Exists: NO
Related CWE:
CPE: a:notepad-plus-plus:notepad++
Platforms Tested: Windows XP SP3 EN
Notepad++ – DSpellCheck v1.2.12.0 plugin[DOS]
The vulnerability exists in the DSpellCheck plugin of Notepad++ version 1.2.12.0. By entering a large number of characters in the 'hunspell dictionaries path' field, an access violation exception occurs, leading to a denial of service.
Mitigation:
Update to a version of the plugin that does not have this vulnerability.