vendor:
RoyalTSX
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Heap Memory Corruption
119
CWE
Product Name: RoyalTSX
Affected Version From: 6.0.1.1000
Affected Version To: 6.0.1.1000
Patch Exists: NO
Related CWE:
CPE: a:royal_apps_gmbh:royal_tsx:6.0.1.1000
Platforms Tested: macOS
2023
RoyalTSX 6.0.1 RTSZ File Handling Heap Memory Corruption PoC
The RoyalTSX application version 6.0.1.1000 for macOS crashes due to a heap memory corruption issue. Specifically, the crash occurs when the SecureGatewayHost object in the RoyalTSXNativeUI processes a hostname with an array of approximately 1600 bytes and the 'Test Connection' function is activated. This results in an instant crash of the application.
Mitigation:
To mitigate this vulnerability, users are advised to avoid inputting excessively large hostnames when using the RoyalTSX application.