PT-2021-23507 · Barrier · Barrier

Matthias Gerstner

·

Published

2021-11-08

·

Updated

2022-07-12

·

CVE-2021-42075

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Barrier versions prior to 2.3.4
Description An issue in the barriers component, which is the server-side implementation of Barrier, fails to correctly close file descriptors for established TCP connections. This allows an unauthenticated remote attacker to cause file descriptor exhaustion in the server process, leading to denial of service.
Recommendations For Barrier versions prior to 2.3.4, update to version 2.3.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the barriers component to minimize the risk of exploitation.

Exploit

Fix

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42075

Affected Products

Barrier