CVE-2011-4815

Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
ruby-langruby
𝑥
≤ 1.8.7-p352
ruby-langruby
1.8.7-p299
ruby-langruby
1.8.7-p302
ruby-langruby
1.8.7-p330
ruby-langruby
1.8.7-p334
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ruby1.8
oneiric
Fixed 1.8.7.352-2ubuntu0.1
released
natty
Fixed 1.8.7.302-2ubuntu0.1
released
maverick
Fixed 1.8.7.299-2ubuntu0.1
released
lucid
Fixed 1.8.7.249-2ubuntu0.1
released
hardy
ignored
ruby1.9
oneiric
dne
natty
dne
maverick
dne
lucid
not-affected
hardy
not-affected
ruby1.9.1
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
dne
References