Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpr8-vpc7-7vfc

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

EPSS

Процентиль: 82%
0.01663
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 14 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

redhat
почти 14 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

nvd
почти 14 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

debian
почти 14 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restri ...

oracle-oval
почти 14 лет назад

ELSA-2012-0069: ruby security update (MODERATE)

EPSS

Процентиль: 82%
0.01663
Низкий

Дефекты

CWE-20