LWN.net Logo

apr: denial of service

Package(s):apr CVE #(s):CVE-2012-0840
Created:February 14, 2012 Updated:March 1, 2012
Description: From the Mandriva advisory:

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Alerts:
Mandriva MDVSA-2012:019 2012-02-14
Fedora FEDORA-2012-1656 2012-03-01
Fedora FEDORA-2012-1709 2012-03-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds