5
CVSSv2

CVE-2012-2328

Published: 10/02/2014 Updated: 30/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

internal/cimxml/sax/NodeFactory.java in Standards-Based Linux Instrumentation for Manageability (SBLIM) Common Information Model (CIM) Client (aka sblim-cim-client2) prior to 2.1.12 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent malicious users to cause a denial of service (CPU consumption) via a crafted XML file.

Vulnerable Product Search on Vulmon Subscribe to Product

opensuse opensuse 11.4

opensuse opensuse 12.2

opensuse opensuse 12.1

standards based linux instrumentation project standards-based linux common information model client

Vendor Advisories

Synopsis Low: sblim-cim-client2 security update Type/Severity Security Advisory: Low Topic Updated sblim-cim-client2 packages that fix one security issue are nowavailable for Red Hat Enterprise Linux 6The Red Hat Security Response Team has rated this update as having lowsecurity impact A Common Vulnerabil ...