Description
GeoGebra CAS Calculator 6.0.631.0 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a payload with 8000 repeated characters and paste it into the calculator's input field to trigger an application crash.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
Credits
Brian Rodriguez
References
www.exploit-db.com/exploits/49655 (ExploitDB-49655)
www.geogebra.org (GeoGebra Official Homepage)
www.vulncheck.com/...ogebra-cas-calculator-denial-of-service (VulnCheck Advisory: GeoGebra CAS Calculator 6.0.631.0 - Denial of Service)