5
CVSSv2

CVE-2012-1150

Published: 05/10/2012 Updated: 25/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Python prior to 2.6.8, 2.7.x prior to 2.7.3, 3.x prior to 3.1.5, and 3.2.x prior to 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent malicious users to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

python python 2.6.6

python python 2.6.5

python python 2.5.3

python python 2.5.6

python python 2.4.4

python python 2.4.2

python python 2.3.2

python python 2.3.1

python python

python python 2.6.6150

python python 2.5.150

python python 2.4.3

python python 2.3.3

python python 2.1.1

python python 2.1.2

python python 1.5.2

python python 1.2

python python 2.6.4

python python 2.6.3

python python 2.5.2

python python 2.5.1

python python 2.4.6

python python 2.4.1

python python 2.3.7

python python 2.2.2

python python 2.0.1

python python 2.0

python python 0.9.0

python python 2.6.2150

python python 2.6.2

python python 2.6.1

python python 2.5.4

python python 2.3.4

python python 2.3.5

python python 2.2.3

python python 2.2.1

python python 2.2

python python 1.6.1

python python 1.6

python python 2.1.3

python python 2.1

python python 1.3

python python 0.9.1

python python 2.7.1

python python 2.7.1150

python python 2.7.2

python python 2.7.2150

python python 3.1

python python 3.0.1

python python 3.1.4

python python 3.1.3

python python 3.1.2

python python 3.1.1

python python 3.0

python python 3.2

python python 3.2.2150

Vendor Advisories

Synopsis Moderate: python security update Type/Severity Security Advisory: Moderate Topic Updated python packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability ...
Synopsis Moderate: python security update Type/Severity Security Advisory: Moderate Topic Updated python packages that fix multiple security issues are now availablefor Red Hat Enterprise Linux 5The Red Hat Security Response Team has rated this update as having moderatesecurity impact Common Vulnerability ...
Debian Bug report logs - #800564 php5: trivial hash complexity DoS attack Package: php5-cli; Maintainer for php5-cli is Debian PHP Maintainers <pkg-php-maint@listsaliothdebianorg>; Source for php5-cli is src:php5 (PTS, buildd, popcon) Reported by: "brian m carlson" <sandals@crustytoothpastenet> Date: Wed, 30 Sep ...
Several security issues were fixed in Python 27 ...
Several security issues were fixed in Python 32 ...
Several security issues were fixed in Python 31 ...
Several security issues were fixed in Python 26 ...
A denial of service flaw was found in the implementation of associative arrays (dictionaries) in Python An attacker able to supply a large number of inputs to a Python application (such as HTTP POST request parameters sent to a web application) that are used as keys when inserting data into an array could trigger multiple hash function collisions, ...

Github Repositories

Software build threat intelligence tool to compare software versions used in projects against CVE/CPE vulnerability data

Falco: 3rd party code security intelligence for software maintainers What is falco? Falco is a simple tool to search the NIST NVD and report latent security bugs in 3rd party software packages in your projects By placing falco in your build or QA process, you can be alerted when new security defects are reported You could make falco part of your architectural review process

CVE database store

Victims CVE Database This database contains information regarding CVE(s) that affect various language modules We currently store version information corresponding to respective modules as understood by select sources Language Module Type Metadata Python PyPi Package name, version Java Maven Artifact groupId, artifactId, version This project is inspired by the gre