Description
Color Notes 1.4 contains a denial of service vulnerability that allows attackers to crash the application by pasting excessively long character strings into note fields. Attackers can generate a payload containing 350,000 repeated characters and paste it twice into a new note to cause the application to stop responding.
Problem types
Memory Allocation with Excessive Size Value
Product status
Credits
Geovanni Ruiz
References
www.exploit-db.com/exploits/49952 (ExploitDB-49952)
www.vulncheck.com/...al-of-service-via-long-character-string (VulnCheck Advisory: Color Notes 1.4 Denial of Service via Long Character String)