Sha256: f6e8c429fc016022eae92ae3e2c6e093407a7c53566b5be924e5c615fa4c6cb0

Contents?: true

Size: 695 Bytes

Versions: 6

Compression:

Stored size: 695 Bytes

Contents

---
engine: ruby
cve: 2012-5371
osvdb: 87863
url: http://www.osvdb.org/show/osvdb/87863
title: Ruby MurmurHash2 Implementation Hash Collision Remote DoS
date: 2012-11-23
description: |
  Ruby contains a flaw related to the MurmurHash2 implementation that may allow
  a remote denial of service. The issue is triggered when hash values are
  computed without having the ability to cause hash collisions restricted. When
  sending specially crafted input to an application maintaining a hash table, a
  context-dependent attacker can cause a consumption of CPU resources. This
  will result in a loss of availability for the program.
cvss_v2: 5.0
patched_versions:
  - ~> 1.9.3.327
  - ">= 2.0.0"

Version data entries

6 entries across 6 versions & 2 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/rubies/ruby/CVE-2012-5371.yml
bundler-budit-0.6.2 data/ruby-advisory-db/rubies/ruby/OSVDB-87863.yml
bundler-budit-0.6.1 data/ruby-advisory-db/rubies/ruby/OSVDB-87863.yml
bundler-audit-0.6.1 data/ruby-advisory-db/rubies/ruby/OSVDB-87863.yml
bundler-audit-0.6.0 data/ruby-advisory-db/rubies/ruby/OSVDB-87863.yml
bundler-audit-0.5.0 data/ruby-advisory-db/rubies/ruby/OSVDB-87863.yml