Lucene search

K
osvGoogleOSV:DLA-209-1
HistoryApr 29, 2015 - 12:00 a.m.

jruby - security update

2015-04-2900:00:00
Google
osv.dev
10

0.01 Low

EPSS

Percentile

83.5%

JRuby before 1.6.5.1 computes hash values without restricting the ability to
trigger hash collisions predictably, which allows context-dependent attackers
to cause a denial of service (CPU consumption) via crafted input to an
application that maintains a hash table. Note: This update includes
corrections to the original fix for later Debian releases to avoid the issues
identified in CVE-2012-5370.