Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2739

Опубликовано: 28 дек. 2011
Источник: redhat
CVSS2: 5
EPSS Низкий

Описание

Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Отчет

This flaw affects various versions of Java as shipped with Red Hat products. A patch is available for Java 7 and Java 8, but not for previous versions of Java shipped with Red Hat products. Although no patch is available for previous versions of Java as shipped with Red Hat products, the impact of this flaw has been addressed in several components that utilize Java HashMap in such a way that may expose a denial of service flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4java-1.5.0-ibmWill not fix
Red Hat Enterprise Linux 4java-1.6.0-ibmWill not fix
Red Hat Enterprise Linux 4java-1.6.0-sunWill not fix
Red Hat Enterprise Linux 5java-1.5.0-ibmWill not fix
Red Hat Enterprise Linux 5java-1.6.0-ibmWill not fix
Red Hat Enterprise Linux 5java-1.6.0-openjdkWill not fix
Red Hat Enterprise Linux 5java-1.6.0-sunWill not fix
Red Hat Enterprise Linux 6java-1.5.0-ibmWill not fix
Red Hat Enterprise Linux 6java-1.6.0-ibmWill not fix
Red Hat Enterprise Linux 6java-1.6.0-openjdkWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=750533java: hash table collisions CPU usage DoS (oCERT-2011-003)

EPSS

Процентиль: 87%
0.0317
Низкий

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 13 лет назад

Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

nvd
больше 13 лет назад

Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

debian
больше 13 лет назад

Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 an ...

github
около 4 лет назад

Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

EPSS

Процентиль: 87%
0.0317
Низкий

5 Medium

CVSS2