PT-2012-4778 · Ocaml · Xml-Light Library

Kurt Seifried

·

Published

2012-08-25

·

Updated

2014-02-12

·

CVE-2012-3514

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions OCaml Xml-Light Library versions prior to r234
Description The issue allows context-dependent attackers to cause a denial of service, specifically CPU consumption, by triggering hash collisions predictably. This is due to the library's computation of hash values without proper restrictions.
Recommendations For versions prior to r234, update to version r234 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3514

Affected Products

Xml-Light Library