SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-0840

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU…

MEDIUM 5.0EPSS 43.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 43.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
43.35% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
apache/portable runtime
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.