CVE-2012-5370
EPSS 0.60%JRuby denial of service via Hash Collision
發布日:2022/5/17修改日:2026/4/28
描述
JRuby computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4838.
受影響套件(2)
- Debian/jrubyfrom 0, < 1.5.6-5
- Maven/org.jruby:jruby-parentfrom 0, < 1.7.1
參考連結(6)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2012-5370
- ADVISORYhttps://security-tracker.debian.org/tracker/CVE-2012-5370
- WEBhttp://jruby.org/2012/12/03/jruby-1-7-1
- WEBhttp://rhn.redhat.com/errata/RHSA-2013-0533.html
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=880671
- WEBhttps://github.com/jruby/jruby/commit/5e4aab28b26fd127112b76fabfac9a33b64caf77