Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
2011-12-30T01:55:01.437
2025-04-11T00:51:21.963
Deferred
CVSSv2: 7.8 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:C
10.0
6.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | ruby-lang | ruby | ≤ 1.8.7-p352 | Yes |
| Application | ruby-lang | ruby | 1.8.7-p299 | Yes |
| Application | ruby-lang | ruby | 1.8.7-p302 | Yes |
| Application | ruby-lang | ruby | 1.8.7-p330 | Yes |
| Application | ruby-lang | ruby | 1.8.7-p334 | Yes |