CVE Database
/

CVE-2011-4838

Back to search

CVE-2011-4838

Published: Dec 30, 2011

Modified: Aug 7, 2024

PUBLISHED

Description

JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

VendorProductVersions

n/a

n/a

affected
n/a

References

jruby-hash-dos(72019)
vdb-entry
x_refsource_XF
50084
third-party-advisory
x_refsource_SECUNIA
47407
third-party-advisory
x_refsource_SECUNIA
VU#903934
third-party-advisory
x_refsource_CERT-VN
RHSA-2012:1232
vendor-advisory
x_refsource_REDHAT
GLSA-201207-06
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now