VDB
CVE-2012-0840
CVE-2012-0840
PUBLISHED
CVSS 5 MEDIUM
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
EPSS 40.19% · 97.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
40.19%
97.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apache | portable_runtime | 0.9.4, 0, 0.9.1 |
| n/a | n/a | n/a |
Timeline
- Feb 10, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- [apr-commits] 20120115 svn commit: r1231605 - /apr/apr/trunk/tables/apr_hash.c mailing-list
- apacheapr-hash-dos(73096) vdb
- [oss-security] 20120208 CVE request: apr - Hash DoS vulnerability mailing-list
- MDVSA-2012:019 vendor-advisory
- 47862 third-party-advisory
- http://svn.apache.org/viewvc?rev=1231605&view=rev url
- [dev] 20120105 Hash collision vectors in APR? mailing-list
- [dev] 20120113 Re: Hash collision vectors in APR? mailing-list
- [oss-security] 20120208 Re: CVE request: apr - Hash DoS vulnerability mailing-list
- [dev] 20120114 Re: Hash collision vectors in APR? mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2012-0840 advisory
- http://mail-archives.apache.org/mod_mbox/apr-commits/201201.mbox/%3C20120115003715.071D423888FD@eris.apache.org%3E url