PT-2012-4778 · Ocaml · Xml-Light Library

Kurt Seifried

·

Publicado

2012-08-25

·

Atualizado

2014-02-12

·

CVE-2012-3514

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OCaml Xml-Light Library versions prior to r234
Description The issue allows context-dependent attackers to cause a denial of service, specifically CPU consumption, by triggering hash collisions predictably. This is due to the library's computation of hash values without proper restrictions.
Recommendations For versions prior to r234, update to version r234 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-3514

Produtos afetados

Xml-Light Library