Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpr8-vpc7-7vfc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

EPSS

Процентиль: 85%
0.02662
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 13 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

redhat
больше 13 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

nvd
больше 13 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

debian
больше 13 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restri ...

oracle-oval
больше 13 лет назад

ELSA-2012-0069: ruby security update (MODERATE)

EPSS

Процентиль: 85%
0.02662
Низкий

Дефекты

CWE-20