CVE-2012-0839

UnknownEPSS 2.75%

Last modified

CVE-2012-0839 is a vulnerability of currently unknown severity. OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.. EPSS estimates a 2.75% chance of exploitation in the next 30 days.

Description

OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Metrics

EPSS Probability
2.75%

84.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
InriaOcaml<= 3.12.1—
InriaOcaml1.07—
InriaOcaml2.02—
InriaOcaml2.04—
InriaOcaml2.99Alpha
InriaOcaml3.00—
InriaOcaml3.01—
InriaOcaml3.02—
InriaOcaml3.03Alpha
InriaOcaml3.04—
InriaOcaml3.05Beta
InriaOcaml3.06—
InriaOcaml3.07—
InriaOcaml3.08—
InriaOcaml3.09—
InriaOcaml3.10—
InriaOcaml3.11—
InriaOcaml3.12—

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-0839?
OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
How severe is CVE-2012-0839?
Severity scoring for CVE-2012-0839 is pending analysis. The EPSS model estimates a 2.75% probability of exploitation in the next 30 days.
How do I fix CVE-2012-0839?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2012

Are you affected by CVE-2012-0839?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST