LWN.net Logo

sblim-cim-client2: predictable hash collisions

Package(s):sblim-cim-client2 CVE #(s):CVE-2012-2328
Created:June 20, 2012 Updated:January 23, 2013
Description: From the Red Hat advisory:

It was found that the Java HashMap implementation was susceptible to predictable hash collisions. SBLIM uses HashMap when parsing XML inputs. A specially-crafted CIM-XML message from a WBEM (Web-Based Enterprise Management) server could cause a SBLIM client to use an excessive amount of CPU. Randomization has been added to help avoid collisions.

Alerts:
Red Hat RHSA-2012:0987-04 2012-06-20
Oracle ELSA-2012-0987 2012-07-02
Scientific Linux SL-sbli-20120709 2012-07-09
CentOS CESA-2012:0987 2012-07-10
openSUSE openSUSE-SU-2012:1621-1 2012-12-07
openSUSE openSUSE-SU-2013:0144-1 2013-01-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds