Oracle Java SE 7 and previous versions, and OpenJDK 7 and previous versions, computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent malicious users to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash3 algorithm, a different vulnerability than CVE-2012-2739.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
oracle jdk |
||
oracle openjdk |
||
oracle jre |