CVE Vulnerabilities

CVE-2012-5370

Published: Nov 28, 2012 | Modified: Jan 18, 2015
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM

JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.

Affected Software

Name Vendor Start Version End Version
Jruby Jruby - (including) - (including)
Jruby Ubuntu lucid *
Jruby Ubuntu oneiric *
Jruby Ubuntu precise *
Jruby Ubuntu quantal *
Jruby Ubuntu raring *
Jruby Ubuntu saucy *
Jruby Ubuntu trusty *
Jruby Ubuntu upstream *
Jruby Ubuntu utopic *
Jruby Ubuntu vivid *
Jruby Ubuntu wily *
Jruby Ubuntu xenial *
Jruby Ubuntu yakkety *
Fuse ESB Enterprise 7.1.0 RedHat *
Red Hat JBoss SOA Platform 5.3 RedHat *

References