Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-0840

Опубликовано: 05 янв. 2012
Источник: redhat
CVSS2: 5
EPSS Средний

Уязвимость отказа в обслуживании (DoS) в файле "tables/apr_hash.c" библиотеки Apache Portable Runtime (APR), связанная с предсказуемыми хэш-коллизиями

Описание

Обнаружена уязвимость в файле tables/apr_hash.c библиотеки Apache Portable Runtime (APR). Библиотека вычисляет хэш-значения без ограничения возможности предсказуемого вызова хэш-коллизий. Это позволяет злоумышленникам, действующим в зависимости от контекста использования приложения (context-dependent), вызвать отказ в обслуживании (чрезмерное потребление ресурсов процессора), передав специально созданные данные в приложение, поддерживающее хэш-таблицу.

Затронутые версии ПО

  • Apache Portable Runtime (APR) до версии 1.4.5

Тип уязвимости

  • Чрезмерное потребление ресурсов процессора (CPU consumption)
  • Отказ в обслуживании (DoS)

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4aprWill not fix
Red Hat Enterprise Linux 5aprWill not fix
Red Hat Enterprise Linux 6aprWill not fix
Red Hat JBoss Enterprise Web Server 1aprFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=781606apr: hash table collisions CPU usage DoS

EPSS

Процентиль: 99%
0.43346
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 14 лет назад

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

nvd
больше 14 лет назад

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

debian
больше 14 лет назад

tables/apr_hash.c in the Apache Portable Runtime (APR) library through ...

github
около 4 лет назад

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

EPSS

Процентиль: 99%
0.43346
Средний

5 Medium

CVSS2