CVE-2011-5036

CVSS v2.0 5 (Medium)
50% Progress
EPSS 0.80 % (82th)
0.80% Progress
Affected Products 1
Advisories 7

Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Weaknesses
CWE-310
Cryptographic Issues
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2011-12-30 01:55:01
(12 years ago)
Updated Date
2013-10-31 03:21:36
(11 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Rack Project Rack 1.1.0 and prior versions cpe:2.3:a:rack_project:rack <= 1.1.0
  Rack Project Rack 1.2.0 cpe:2.3:a:rack_project:rack:1.2.0
  Rack Project Rack 1.2.1 cpe:2.3:a:rack_project:rack:1.2.1
  Rack Project Rack 1.2.2 cpe:2.3:a:rack_project:rack:1.2.2
  Rack Project Rack 1.2.3 cpe:2.3:a:rack_project:rack:1.2.3
  Rack Project Rack 1.2.4 cpe:2.3:a:rack_project:rack:1.2.4
  Rack Project Rack 1.3.0 cpe:2.3:a:rack_project:rack:1.3.0
  Rack Project Rack 1.3.1 cpe:2.3:a:rack_project:rack:1.3.1
  Rack Project Rack 1.3.2 cpe:2.3:a:rack_project:rack:1.3.2
  Rack Project Rack 1.3.3 cpe:2.3:a:rack_project:rack:1.3.3
  Rack Project Rack 1.3.4 cpe:2.3:a:rack_project:rack:1.3.4
  Rack Project Rack 1.3.5 cpe:2.3:a:rack_project:rack:1.3.5
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...