CVE-2011-4815

CVSS v2.0 7.8 (High)
78% Progress
EPSS 2.02 % (89th)
2.02% Progress
Affected Products 1
Advisories 11

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Weaknesses
CWE-20
Improper Input Validation
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2011-12-30 01:55:01
(12 years ago)
Updated Date
2017-08-29 01:30:35
(7 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Ruby-lang Ruby 1.8.7-p352 and prior versions cpe:2.3:a:ruby-lang:ruby <= 1.8.7-p352
  Ruby-lang Ruby 1.8.7-p299 cpe:2.3:a:ruby-lang:ruby:1.8.7-p299
  Ruby-lang Ruby 1.8.7-p302 cpe:2.3:a:ruby-lang:ruby:1.8.7-p302
  Ruby-lang Ruby 1.8.7-p330 cpe:2.3:a:ruby-lang:ruby:1.8.7-p330
  Ruby-lang Ruby 1.8.7-p334 cpe:2.3:a:ruby-lang:ruby:1.8.7-p334
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...