Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-4815

Опубликовано: 30 дек. 2011
Источник: nvd
CVSS2: 7.8
EPSS Низкий

Описание

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*
Версия до 1.8.7-p352 (включая)
cpe:2.3:a:ruby-lang:ruby:1.8.7-p299:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7-p302:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7-p330:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7-p334:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02662
Низкий

7.8 High

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 13 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

redhat
больше 13 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

debian
больше 13 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restri ...

github
больше 3 лет назад

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

oracle-oval
больше 13 лет назад

ELSA-2012-0069: ruby security update (MODERATE)

EPSS

Процентиль: 85%
0.02662
Низкий

7.8 High

CVSS2

Дефекты

CWE-20