CVE-2021-47876

7.5

GeoGebra · Classic 5

GeoGebra Classic 5.0.631.0-d is susceptible to a denial of service vulnerability via an oversized input buffer, which can trigger an application crash.

Executive summary

A heap-based resource exhaustion vulnerability in GeoGebra Classic 5 allows a local attacker to crash the application, resulting in a denial of service.

Vulnerability

The application fails to properly throttle or limit resources during input processing, specifically within the "Entrada:" field. An attacker can supply a large buffer of 800,000 characters to trigger an application crash, requiring no authentication to exploit.

Business impact

While the CVSS score is 7.5, the impact is primarily localized to the availability of the application on the affected workstation. Successful exploitation results in a denial of service, which can disrupt educational or professional workflows that rely on the software. While this does not lead to remote code execution or data theft, the forced termination of the software may result in the loss of unsaved work and temporary productivity impairment.

Remediation

Immediate Action: Users should update to the latest available version of GeoGebra Classic to ensure all known resource management patches are applied.

Proactive Monitoring: IT administrators should monitor workstation event logs for recurring application crashes or unexpected terminations of the GeoGebra process.

Compensating Controls: As this is a local exploit, endpoint security policies should be enforced to restrict the execution of unauthorized scripts or tools that might be used to automate the delivery of the malicious buffer.

Exploitation status

Public Exploit Available: Yes — a proof of concept exists via ExploitDB (EDB-ID: 49654).

Analyst recommendation

The vulnerability presents a clear risk to application availability on affected systems. Organizations utilizing GeoGebra Classic should prioritize updating to the most recent version provided by the vendor. If an immediate update is not feasible, users should be cautioned against pasting untrusted or unusually large blocks of text into the application input fields to avoid triggering the crash.

More GeoGebra CVEs

Sources

Originally found and disclosed by Brian Rodriguez, per the CVE Program record.