PT-2021-23311 · Rare Technologies · Bounter

Awen-Li

+1

·

Published

2021-12-17

·

Updated

2021-12-27

·

CVE-2021-41497

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions RaRe-Technologies bounter versions 1.01 through 1.10
Description The issue allows attackers to conduct Denial of Service attacks by inputting a huge width of hash bucket, due to a null pointer reference in CMS Conservative increment obj.
Recommendations For versions 1.01 through 1.10, consider restricting the input width of hash bucket to prevent Denial of Service attacks until a patch is available. As a temporary workaround, consider implementing input validation to limit the width of hash bucket.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41497
GHSA-74XW-GWFM-7PV7
PYSEC-2021-880

Affected Products

Bounter