Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2011-4461

Опубликовано: 28 дек. 2011
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Отчет

The Red Hat Security Response Team has rated this issue as having Low security impact for the jetty-eclipse package in Red Hat Enterprise Linux 6. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6jetty-eclipseWill not fix
Fuse ESB Enterprise 7.1.0FixedRHSA-2012:160421.12.2012
Fuse Management Console 7.1.0FixedRHSA-2012:160621.12.2012
Fuse MQ Enterprise 7.1.0FixedRHSA-2012:160521.12.2012

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=781677jetty: hash table collisions CPU usage DoS (oCERT-2011-003)

EPSS

Процентиль: 86%
0.03003
Низкий

5 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 14 лет назад

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS3: 5.3
nvd
около 14 лет назад

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

CVSS3: 5.3
debian
около 14 лет назад

Jetty 8.1.0.RC2 and earlier computes hash values for form parameters w ...

CVSS3: 5.3
github
больше 3 лет назад

Improper Input Validation in Jetty

EPSS

Процентиль: 86%
0.03003
Низкий

5 Medium

CVSS2