PT-2023-22378 · Unknown · Call Blocker
Published
2023-05-30
·
Updated
2025-01-13
·
CVE-2023-29726
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Call Blocker application version 6.6.3
Description
The issue allows an attacker to inject large amounts of data into the application's database, causing it to crash due to an out-of-memory (OOM) error when it loads the data into memory on startup, resulting in a persistent denial of service.
Recommendations
For Call Blocker application version 6.6.3, consider restricting access to the database to prevent data injection until a patch is available. As a temporary workaround, limiting the amount of data that can be loaded into memory may help mitigate the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Call Blocker