Vulnerability Name: | CVE-2011-5036 (CCN-72014) | ||||||||||||||||||||||||||||
Assigned: | 2011-12-28 | ||||||||||||||||||||||||||||
Published: | 2011-12-28 | ||||||||||||||||||||||||||||
Updated: | 2013-10-31 | ||||||||||||||||||||||||||||
Summary: | Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-310 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20111228 n.runs-SA-2011.004 - web programming languages and platforms - DoS through hash table Source: MITRE Type: CNA CVE-2011-5036 Source: CCN Type: Rack Web site Rack: a Ruby Webserver Interface Source: CCN Type: Rack Web page Rack Source: CCN Type: SA47414 Rack Web Form Hash Collision Denial of Service Vulnerability Source: DEBIAN Type: UNKNOWN DSA-2783 Source: DEBIAN Type: DSA-2783 librack-ruby -- several vulnerabilities Source: CCN Type: US-CERT VU#903934 Hash table implementations vulnerable to algorithmic complexity attacks Source: CERT-VN Type: US Government Resource VU#903934 Source: CCN Type: n.runs-SA-2011.004 Denial of Service through hash table multi-collisions Source: MISC Type: UNKNOWN http://www.nruns.com/_downloads/advisory28122011.pdf Source: CCN Type: oCERT-2011-003 multiple implementations denial-of-service via hash algorithm collision Source: MISC Type: UNKNOWN http://www.ocert.org/advisories/ocert-2011-003.html Source: CCN Type: OSVDB ID: 78121 Rack Hash Collision Form Parameter Parsing Remote DoS Source: CCN Type: BID-51197 Rack Hash Collision Denial Of Service Vulnerability Source: XF Type: UNKNOWN rack-hash-dos(72014) Source: CONFIRM Type: Exploit https://gist.github.com/52bbc6b9cc19ce330829 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |