Уязвимость отказа в обслуживании (DoS) в файле "tables/apr_hash.c" библиотеки Apache Portable Runtime (APR), связанная с предсказуемыми хэш-коллизиями
Описание
Обнаружена уязвимость в файле tables/apr_hash.c библиотеки Apache Portable Runtime (APR). Библиотека вычисляет хэш-значения без ограничения возможности предсказуемого вызова хэш-коллизий. Это позволяет злоумышленникам, действующим в зависимости от контекста использования приложения (context-dependent), вызвать отказ в обслуживании (чрезмерное потребление ресурсов процессора), передав специально созданные данные в приложение, поддерживающее хэш-таблицу.
Затронутые версии ПО
- Apache Portable Runtime (APR) до версии 1.4.5
Тип уязвимости
- Чрезмерное потребление ресурсов процессора (CPU consumption)
- Отказ в обслуживании (DoS)
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 4 | apr | Will not fix | ||
| Red Hat Enterprise Linux 5 | apr | Will not fix | ||
| Red Hat Enterprise Linux 6 | apr | Will not fix | ||
| Red Hat JBoss Enterprise Web Server 1 | apr | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5 Medium
CVSS2
Связанные уязвимости
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
tables/apr_hash.c in the Apache Portable Runtime (APR) library through ...
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
EPSS
5 Medium
CVSS2