CVE-2012-0839

UnknownEPSS 2.75%

Last modified

CVE-2012-0839 is a vulnerability of currently unknown severity. OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.. EPSS estimates a 2.75% chance of exploitation in the next 30 days.

Description

OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Metrics

EPSS Probability
2.75%

84.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
InriaOcaml<= 3.12.1
InriaOcaml1.07
InriaOcaml2.02
InriaOcaml2.04
InriaOcaml2.99Alpha
InriaOcaml3.00
InriaOcaml3.01
InriaOcaml3.02
InriaOcaml3.03Alpha
InriaOcaml3.04
InriaOcaml3.05Beta
InriaOcaml3.06
InriaOcaml3.07
InriaOcaml3.08
InriaOcaml3.09
InriaOcaml3.10
InriaOcaml3.11
InriaOcaml3.12

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-0839?
OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
How severe is CVE-2012-0839?
Severity scoring for CVE-2012-0839 is pending analysis. The EPSS model estimates a 2.75% probability of exploitation in the next 30 days.
How do I fix CVE-2012-0839?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-0839?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST