Lucene search

K
cve[email protected]CVE-2012-0840
HistoryFeb 10, 2012 - 7:55 p.m.

CVE-2012-0840

2012-02-1019:55:02
CWE-20
web.nvd.nist.gov
26
cve-2012-0840
apache portable runtime
apr
hash table
denial of service
cpu consumption
security vulnerability
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.2 Medium

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.1%

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Affected configurations

NVD
Node
apacheportable_runtimeRange1.4.5
OR
apacheportable_runtimeMatch0.9.1
OR
apacheportable_runtimeMatch0.9.2
OR
apacheportable_runtimeMatch0.9.2-dev
OR
apacheportable_runtimeMatch0.9.3
OR
apacheportable_runtimeMatch0.9.3-dev
OR
apacheportable_runtimeMatch0.9.4
OR
apacheportable_runtimeMatch0.9.5
OR
apacheportable_runtimeMatch0.9.6
OR
apacheportable_runtimeMatch0.9.7
OR
apacheportable_runtimeMatch0.9.7-dev
OR
apacheportable_runtimeMatch0.9.8
OR
apacheportable_runtimeMatch0.9.9
OR
apacheportable_runtimeMatch0.9.16-dev
OR
apacheportable_runtimeMatch1.3.0
OR
apacheportable_runtimeMatch1.3.1
OR
apacheportable_runtimeMatch1.3.2
OR
apacheportable_runtimeMatch1.3.3
OR
apacheportable_runtimeMatch1.3.4
OR
apacheportable_runtimeMatch1.3.4-dev
OR
apacheportable_runtimeMatch1.3.5
OR
apacheportable_runtimeMatch1.3.6
OR
apacheportable_runtimeMatch1.3.6-dev
OR
apacheportable_runtimeMatch1.3.7
OR
apacheportable_runtimeMatch1.3.8
OR
apacheportable_runtimeMatch1.3.9
OR
apacheportable_runtimeMatch1.3.10
OR
apacheportable_runtimeMatch1.3.11
OR
apacheportable_runtimeMatch1.3.12
OR
apacheportable_runtimeMatch1.3.13
OR
apacheportable_runtimeMatch1.4.0
OR
apacheportable_runtimeMatch1.4.1
OR
apacheportable_runtimeMatch1.4.2
OR
apacheportable_runtimeMatch1.4.3
OR
apacheportable_runtimeMatch1.4.4

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

6.2 Medium

AI Score

Confidence

High

0.008 Low

EPSS

Percentile

82.1%