Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2012-5371

Опубликовано: 28 нояб. 2012
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5

Описание

Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against a variant of the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4815.

РелизСтатусПримечание
devel

not-affected

1.8.7.358-6ubuntu1
hardy

ignored

end of life
lucid

not-affected

1.8.7.249-2ubuntu0.2
oneiric

not-affected

1.8.7.352-2ubuntu0.2
precise

not-affected

1.8.7.352-2ubuntu1.1
quantal

not-affected

1.8.7.358-4ubuntu0.1
raring

not-affected

1.8.7.358-6ubuntu1
saucy

not-affected

1.8.7.358-6ubuntu1
upstream

not-affected

Показывать по

РелизСтатусПримечание
devel

released

1.9.3.194-7ubuntu1
hardy

DNE

lucid

ignored

end of life
oneiric

ignored

end of life
precise

released

1.9.3.0-1ubuntu2.5
quantal

released

1.9.3.194-1ubuntu1.3
raring

released

1.9.3.194-7ubuntu1
saucy

released

1.9.3.194-7ubuntu1
upstream

released

1.9.3.194-4, 1.9.3 pl 327

Показывать по

EPSS

Процентиль: 86%
0.0281
Низкий

5 Medium

CVSS2

Связанные уязвимости

redhat
около 13 лет назад

Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against a variant of the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4815.

nvd
около 13 лет назад

Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against a variant of the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4815.

debian
около 13 лет назад

Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes ...

github
больше 3 лет назад

Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against a variant of the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4815.

EPSS

Процентиль: 86%
0.0281
Низкий

5 Medium

CVSS2