LWN.net Logo

ocaml-xml-light: denial of service

Package(s):ocaml-xml-light CVE #(s):CVE-2012-3514
Created:August 31, 2012 Updated:April 10, 2013
Description: From the CVE entry:

OCaml Xml-Light Library before r234 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via unspecified vectors.

Alerts:
Fedora FEDORA-2012-12500 2012-08-31
Mageia MGASA-2012-0266 2012-09-13
Mandriva MDVSA-2013:107 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds