CVE-2011-4815

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ruby-lang:ruby:1.8.7-p334:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7-p330:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7-p302:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:1.8.7-p299:*:*:*:*:*:*:*
cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:*

Information

Published : 2011-12-29 17:55

Updated : 2017-08-28 18:30


NVD link : CVE-2011-4815

Mitre link : CVE-2011-4815


JSON object : View

CWE
CWE-20

Improper Input Validation

Advertisement

dedicated server usa

Products Affected

ruby-lang

  • ruby