vendor:
Textpad
by:
Gionathan Reale
5.5
CVSS
MEDIUM
Denial of Service
400
CWE
Product Name: Textpad
Affected Version From: 8.1.2002
Affected Version To: 8.1.2002
Patch Exists: NO
Related CWE:
CPE: a:textpad:textpad:8.1.2
Platforms Tested: Windows 7 32-bit
2018
Textpad 8.1.2 – Denial Of Service (PoC)
The exploit script creates a file with a large payload, causing the Textpad application to crash when the payload is pasted into a specific field in the program. This leads to a denial of service.
Mitigation:
Update Textpad to a version that fixes the vulnerability. Avoid opening untrusted files or copying large amounts of text into the program.