Hash Collision Vulnerability in GLib by GNOME
CVE-2012-0039

7.5HIGH

Key Information:

Vendor
Gnome
Status
Vendor
CVE Published:
14 January 2012

Summary

GLib versions up to 2.31.8 are susceptible to a vulnerability in the g_str_hash function that allows attackers to create predictable hash collisions. This could lead to potential denial-of-service conditions through excessive CPU consumption caused by crafted input targeting applications that utilize hash tables. Although the function itself is not inherently vulnerable, the lack of limitations on hash collision triggering poses risks for users relying on default implementations.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2012-0039 : Hash Collision Vulnerability in GLib by GNOME | SecurityVulnerability.io