PT-2011-5121 · Ruby+3 · Ruby+3

Alexander Klink

+1

·

Publicado

2011-12-29

·

Atualizado

2017-08-29

·

CVE-2011-4815

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Ruby versions prior to 1.8.7-p357
Description The issue allows context-dependent attackers to cause a denial of service, specifically CPU consumption, by providing crafted input to an application that maintains a hash table, thus triggering hash collisions predictably.
Recommendations For versions prior to 1.8.7-p357, update to version 1.8.7-p357 or later to resolve the issue.

Correção

DoS

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CESA-2012_0069
CVE-2011-4815
DLA-88-1
RHSA-2012:0069
RHSA-2012:0070
RHSA-2012_0069
RHSA-2012_0070
RHSA-2026:7305
RHSA-2026:7307
RHSA-2026:8838

Produtos afetados

Centos
Red Hat
Ruby
Suse