PT-2011-5121 · Ruby+3 · Ruby+3
Alexander Klink
+1
·
Published
2011-12-29
·
Updated
2017-08-29
·
CVE-2011-4815
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Ruby versions prior to 1.8.7-p357
Description
The issue allows context-dependent attackers to cause a denial of service, specifically CPU consumption, by providing crafted input to an application that maintains a hash table, thus triggering hash collisions predictably.
Recommendations
For versions prior to 1.8.7-p357, update to version 1.8.7-p357 or later to resolve the issue.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Red Hat
Ruby
Suse