CVE-2012-0840
35Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 43%
from disclosure to weapon0 days
Published on NVDFeb 10
1st PoCJan 5
exploitation probability
43%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/36669⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://mail-archives.apache.org/mod_mbox/apr-commits/201201.mbox/%3C20120115003715.071D423888FD%40eris.apache.org%3Ehttp://openwall.com/lists/oss-security/2012/02/08/3http://openwall.com/lists/oss-security/2012/02/09/1http://secunia.com/advisories/47862https://exchange.xforce.ibmcloud.com/vulnerabilities/73096http://svn.apache.org/viewvc?rev=1231605&view=revhttp://www.mail-archive.com/dev%40apr.apache.org/msg24439.htmlhttp://www.mail-archive.com/dev%40apr.apache.org/msg24472.htmlhttp://www.mail-archive.com/dev%40apr.apache.org/msg24473.htmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2012:019