Denial of Service Vulnerability in Rack by Rackspace
CVE-2011-5036

Currently unrated

Key Information:

Status
Vendor
CVE Published:
30 December 2011

What is CVE-2011-5036?

The Rack library prior to versions 1.1.3, 1.2.5, and 1.3.6 contains a vulnerability where hash values for form parameters are computed without adequate restrictions. This oversight allows remote attackers to exploit predictable hash collisions, potentially leading to a denial of service attack by consuming extensive CPU resources through crafted requests. This issue can significantly hamper application performance and availability.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2011-5036 : Denial of Service Vulnerability in Rack by Rackspace