5
CVSSv2

CVE-2012-0839

Published: 08/02/2012 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

OCaml 3.12.1 and previous versions computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent malicious users to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Vulnerable Product Search on Vulmon Subscribe to Product

inria ocaml 3.01

inria ocaml 3.07

inria ocaml 3.04

inria ocaml

inria ocaml 3.12

inria ocaml 3.02

inria ocaml 1.07

inria ocaml 3.10

inria ocaml 2.04

inria ocaml 3.08

inria ocaml 3.09

inria ocaml 2.02

inria ocaml 3.11

inria ocaml 3.05

inria ocaml 3.00

inria ocaml 3.06

inria ocaml 3.03

inria ocaml 2.99

Vendor Advisories

Debian Bug report logs - #659149 CVE-2012-0839: Hash collision DoS Package: ocaml; Maintainer for ocaml is Debian OCaml Maintainers <debian-ocaml-maint@listsdebianorg>; Source for ocaml is src:ocaml (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 8 Feb 2012 17:48:01 UTC Severity: ...