PT-2012-5957 · Oracle+1 · Oracle Java Se+1
Jan Lieskovsky
·
Published
2012-11-28
·
Updated
2017-08-29
·
CVE-2012-5373
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Java SE versions prior to 8
OpenJDK versions prior to 8
Description
The issue allows context-dependent attackers to cause a denial of service via crafted input to an application that maintains a hash table. This is demonstrated by a universal multicollision attack against the MurmurHash3 algorithm.
Recommendations
For Oracle Java SE versions prior to 8, update to version 8 or later to resolve the issue.
For OpenJDK versions prior to 8, update to version 8 or later to resolve the issue.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openjdk
Oracle Java Se