PT-2021-23389 · Faust+1 · Faust+1

Elmanto

·

Published

2021-12-31

·

Updated

2024-11-19

·

CVE-2021-41737

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Faust version 2.23.1
Description The issue arises when an input file contains specific lines, including "// r visualisation tCst", "//process = +: L: abM-^Q;", and "process = route(3333333333333333333,2,1,2,3,1) : *;", leading to stack consumption. This poses a high risk and has been exploited in specific versions.
Recommendations For Faust version 2.23.1, update to the latest version available to mitigate the risk of stack consumption due to the vulnerable input file processing.

Fix

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2021-41737

Affected Products

Debian
Faust