LWN.net Logo

jruby: denial of service

Package(s):jruby CVE #(s):CVE-2011-4838
Created:July 10, 2012 Updated:July 11, 2012
Description: From the CVE entry:

JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Alerts:
Gentoo 201207-06 2012-07-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds