vendor:
RoyalTSX
by:
Gjoko 'LiquidWorm' Krstic
6.1
CVSS
HIGH
Heap Memory Corruption
119
CWE
Product Name: RoyalTSX
Affected Version From: 6.0.1
Affected Version To: 6.0.1
Patch Exists: NO
Related CWE:
CPE: a:royal_apps_gmbh:royaltsx:6.0.1
Platforms Tested: macOS
2023
RoyalTSX 6.0.1 RTSZ File Handling Heap Memory Corruption PoC
The RoyalTSX application crashes when a specific function is handling the SecureGatewayHost object in the RoyalTSXNativeUI due to a heap memory corruption issue. This occurs when a hostname with an array of approximately 1600 bytes is provided, leading to an instant crash when the 'Test Connection' feature is used.
Mitigation:
To mitigate this vulnerability, users are advised to avoid inputting excessively long hostnames when using the 'Test Connection' feature in RoyalTSX.