PT-2021-28365 · Rare Technologies · Bounter
Published
2021-12-17
·
Updated
2021-12-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
RaRe-Technologies bounter versions 1.01 through 1.10
Description:
The issue is related to a null pointer reference in the
CMS Conservative increment obj function, which allows attackers to conduct Denial of Service attacks. This can be achieved by inputting a huge width of hash bucket.Recommendations:
For versions 1.01 through 1.10, consider restricting the input width of hash bucket to prevent Denial of Service attacks until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bounter