CVE Database
/

CVE-2011-4815

Back to search

CVE-2011-4815

Published: Dec 30, 2011

Modified: Aug 7, 2024

PUBLISHED

Description

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

VendorProductVersions

n/a

n/a

affected
n/a

References

47405
third-party-advisory
x_refsource_SECUNIA
1026474
vdb-entry
x_refsource_SECTRACK
47822
third-party-advisory
x_refsource_SECUNIA
RHSA-2012:0070
vendor-advisory
x_refsource_REDHAT
JVN#90615481
third-party-advisory
x_refsource_JVN
ruby-hash-dos(72020)
vdb-entry
x_refsource_XF
VU#903934
third-party-advisory
x_refsource_CERT-VN
RHSA-2012:0069
vendor-advisory
x_refsource_REDHAT
APPLE-SA-2012-05-09-1
vendor-advisory
x_refsource_APPLE
JVNDB-2012-000066
third-party-advisory
x_refsource_JVNDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now