VDB

DEBIAN-CVE-2011-5036

DEBIAN-CVE-2011-5036 PUBLISHED CVSS 8.699999809265137 HIGH

Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Risk Scores

CVSS v4.0
8.699999809265137
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debian:14ruby-rack0, 0, 0
Debian:12ruby-rack0, 0, 0
Debian:11ruby-rack0, 0, 0
Debian:13ruby-rack0, 0, 0

Timeline

  • Dec 30, 2011 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›