vendor:
HeidiSQL Portable
by:
Victor Mondragón
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: HeidiSQL Portable
Affected Version From: 10.1.0.5464
Affected Version To: 10.1.0.5464
Patch Exists: Yes
Related CWE: N/A
CPE: a:heidisql:heidisql_portable:10.1.0.5464
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Single Language x64 / Windows 7 x32 Service Pack 1
2019
HeidiSQL Portable 10.1.0.5464 – Denial of Service (PoC)
HeidiSQL Portable 10.1.0.5464 is vulnerable to a denial of service attack. By running the python code HeidiSQL_Portable_10.1.0.5464.py, a file bd_p.txt is created with 2000 'A' characters. When this file is copied to the clipboard and pasted into the 'Password' field of the 'Login' window, the application crashes.
Mitigation:
Upgrade to the latest version of HeidiSQL Portable 10.1.0.5464.