Notepad++: Stack Buffer Overflow in Plugin Lexer Loading via Unchecked GetLexerCount() Return Value
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6
exploitation probability
—
observed exploitation
nono source reports it
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, Notepad++ contains a stack buffer overflow in PluginsManager::loadPluginFromPath in PowerEditor/src/MISC/PluginsManager/PluginsManager.cpp because the plugin-supplied GetLexerCount() result controls a loop that writes to containers[30] without enforcing NB_MAX_EXTERNAL_LANG. A malicious or compromised plugin that reports more than 30 lexers can write beyond the stack array and corrupt control data, which can permit arbitrary code execution in the Notepad++ process context. This issue is fixed in version 8.9.8.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected products
notepad-plus-plus · notepad-plus-plusReferences
https://github.com/notepad-plus-plus/notepad-plus-plus/commit/70b88f95311d88523cde6be1b1ec938aa48c24bchttps://github.com/notepad-plus-plus/notepad-plus-plus/commit/f1e1c71b090d69ca0f0175ab73895da41db67a16https://github.com/notepad-plus-plus/notepad-plus-plus/releases/tag/v8.9.8https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-h2wq-6x75-h8q2https://notepad-plus-plus.org/news/v898-released