PT-2021-23311 · Rare Technologies · Bounter
Awen-Li
+1
·
Published
2021-12-17
·
Updated
2021-12-27
·
CVE-2021-41497
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
RaRe-Technologies bounter versions 1.01 through 1.10
Description
The issue allows attackers to conduct Denial of Service attacks by inputting a huge width of hash bucket, due to a null pointer reference in
CMS Conservative increment obj.Recommendations
For versions 1.01 through 1.10, consider restricting the input width of hash bucket to prevent Denial of Service attacks until a patch is available.
As a temporary workaround, consider implementing input validation to limit the width of hash bucket.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bounter