LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser hang) via an HTML document because the resource consumption of onloadwff.js grows with the number of INPUT elements.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://twitter.com/LastPassHelp/status/955478245650071552 | issue tracking third party advisory |
https://forums.lastpass.com/viewtopic.php?f=12&t=286955 | issue tracking third party advisory |
https://www.youtube.com/watch?v=wTcYWZwq3TE | third party advisory exploit |