Skip to content

Global buffer read overflow in nsCodingStateMachine::NextState

Moderate
donho published GHSA-67mm-g35x-jv47 Sep 8, 2023

Package

No package listed

Affected versions

<= 8.5.6

Patched versions

v8.5.7

Description

Summary

Notepad++ uses a diverged copy of the uchardet library. A crafted file allows reading past the bounds of a globally allocated object buffer on file open operation.

Impact

This issue may be used to leak internal memory allocation information.

Severity

Moderate

CVE ID

No known CVE

Weaknesses

Credits