PT-2012-2900 · Apache · Apache Portable Runtime (Apr) Library

William A. Rowe Jr

·

Publicado

2012-02-10

·

Atualizado

2017-12-05

·

CVE-2012-0840

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Apache Portable Runtime (APR) library versions through 1.4.5
Description The issue allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, due to the computation of hash values without restricting the ability to trigger hash collisions predictably.
Recommendations For versions through 1.4.5, update to a version that addresses this issue to prevent denial of service attacks.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-0840

Produtos afetados

Apache Portable Runtime (Apr) Library