Oracle Java SE before 7 Update 6, and OpenJDK 7 before 7u6 build 12 and 8 before build 39, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jdk | Oracle | * | 1.7.0 (including) |
Jdk | Oracle | 1.7.0 (including) | 1.7.0 (including) |
Jdk | Oracle | 1.7.0-update1 (including) | 1.7.0-update1 (including) |
Jdk | Oracle | 1.7.0-update2 (including) | 1.7.0-update2 (including) |
Jdk | Oracle | 1.7.0-update3 (including) | 1.7.0-update3 (including) |
Jdk | Oracle | 1.7.0-update4 (including) | 1.7.0-update4 (including) |
Jre | Oracle | * | 1.7.0 (including) |
Jre | Oracle | 1.7.0 (including) | 1.7.0 (including) |
Jre | Oracle | 1.7.0-update1 (including) | 1.7.0-update1 (including) |
Jre | Oracle | 1.7.0-update2 (including) | 1.7.0-update2 (including) |
Jre | Oracle | 1.7.0-update3 (including) | 1.7.0-update3 (including) |
Jre | Oracle | 1.7.0-update4 (including) | 1.7.0-update4 (including) |
Openjdk-6 | Ubuntu | hardy | * |
Openjdk-6 | Ubuntu | lucid | * |
Openjdk-6 | Ubuntu | natty | * |
Openjdk-6 | Ubuntu | oneiric | * |
Openjdk-6 | Ubuntu | precise | * |
Openjdk-6 | Ubuntu | quantal | * |
Openjdk-6 | Ubuntu | upstream | * |
Openjdk-6b18 | Ubuntu | lucid | * |
Openjdk-6b18 | Ubuntu | natty | * |
Openjdk-6b18 | Ubuntu | oneiric | * |
Openjdk-7 | Ubuntu | oneiric | * |
Openjdk-7 | Ubuntu | precise | * |
Openjdk-7 | Ubuntu | quantal | * |
Openjdk-7 | Ubuntu | upstream | * |
Sun-java5 | Ubuntu | hardy | * |
Sun-java6 | Ubuntu | hardy | * |