CVE-2012-0039
published 2012-01-14CVE-2012-0039: GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably…
PriorityP335high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.16%
80.2th percentile
GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.
Affected
258 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glib2.0 | — | — |
| gnome | glib | <= 2.31.8 | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
| gnome | glib | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-0039: glib2.0 - GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash val...
vendor_debian·2012·CVSS 7.5
CVE-2012-0039 [HIGH] CVE-2012-0039: glib2.0 - GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash val...
GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Red Hat
glib2: hash table collisions CPU usage DoS
vendor_redhat·2003-05-29·CVSS 7.5
CVE-2012-0039 [HIGH] glib2: hash table collisions CPU usage DoS
glib2: hash table collisions CPU usage DoS
GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.
Package: glib2 (Red Hat Enterprise Linux 4) - Affected
Package: glib2 (Red Hat Enterprise Linux 5) - Affected
Package: glib2 (Red Hat Enterprise Linux 6) - Affected
GHSA
GHSA-7w5v-h2pc-qqwc: ** DISPUTED ** GLib 2
ghsa_unreviewed·2022-05-04
CVE-2012-0039 [MEDIUM] GHSA-7w5v-h2pc-qqwc: ** DISPUTED ** GLib 2
** DISPUTED ** GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.
OSV
CVE-2012-0039: GLib 2
osv·2012-01-14·CVSS 7.5
CVE-2012-0039 [HIGH] CVE-2012-0039: GLib 2
GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3387 CVE-2012-3388 CVE-2012-3389 CVE-2012-3390 CVE-2012-3391 CVE-2012-3392 CVE-2012-3393 CVE-2012-3394 CVE-2012-3395 CVE-2012-3396 CVE-2012-3397 CVE-2012-3398 moodle: upstream 2.3.1, 2.2.4, 2
bugzilla·2012-07-20·CVSS 4.0
CVE-2012-3387 [MEDIUM] CVE-2012-3387 CVE-2012-3388 CVE-2012-3389 CVE-2012-3390 CVE-2012-3391 CVE-2012-3392 CVE-2012-3393 CVE-2012-3394 CVE-2012-3395 CVE-2012-3396 CVE-2012-3397 CVE-2012-3398 moodle: upstream 2.3.1, 2.2.4, 2
CVE-2012-3387 CVE-2012-3388 CVE-2012-3389 CVE-2012-3390 CVE-2012-3391 CVE-2012-3392 CVE-2012-3393 CVE-2012-3394 CVE-2012-3395 CVE-2012-3396 CVE-2012-3397 CVE-2012-3398 moodle: upstream 2.3.1, 2.2.4, 2.1.7, 2.0.10, 1.9.19 security fixes
Moodle upstream has released versions 2.3.1, 2.2.4, 2.1.7, 2.0.10, and 1.9.19 to fix the following security flaws:
CVE-2012-3387 Moodle: MSA-12-0039: File upload validation issue
CVE-2012-3388 Moodle: MSA-12-0040: Capabilities issue through caching
CVE-2012-3389 Moodle: MSA-12-0041: XSS issue in LTI module
CVE-2012-3390 Moodle: MSA-12-0042: File access issue in blocks
CVE-2012-3391 Moodle: MSA-12-0043: Early information access issue in forum
CVE-2012-3392 Moodle: MSA-12-0044: Capability check issue in forum subscriptions
CVE-2012-3393 Moodle: MSA-12-0045:
Bugzilla
CVE-2012-0039 glib2: hash table collisions CPU usage DoS
bugzilla·2012-01-09·CVSS 7.5
CVE-2012-0039 [HIGH] CVE-2012-0039 glib2: hash table collisions CPU usage DoS
CVE-2012-0039 glib2: hash table collisions CPU usage DoS
It was reported [1] (and the original report [2]) that glib2 also suffers from algorithmic complexity attacks as described in oCERT-2011-003. While this was originally reported to upstream in 2003, it does not look as though anything was done to correct the problem. According to the Debian report, current glib2 is still vulnerable.
Doing a lookup on other g_str_hash() functions, the following packages may also be vulnerable if they copied code from glib2:
arts-1.5.10/flow/gsl/gslglib.c:172: guint g_str_hash (gconstpointer key)
gettext-0.17/gettext-tools/gnulib-lib/glib/gstring.c:97: g_str_hash (gconstpointer v)
pkg-config-0.23/glib-1.2.10/gstring.c:72: g_str_hash (gconstpointer key)
In addition to the above, the following are als
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655044http://mail.gnome.org/archives/gtk-devel-list/2003-May/msg00111.htmlhttp://openwall.com/lists/oss-security/2012/01/10/12https://bugzilla.redhat.com/show_bug.cgi?id=772720http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=655044http://mail.gnome.org/archives/gtk-devel-list/2003-May/msg00111.htmlhttp://openwall.com/lists/oss-security/2012/01/10/12https://bugzilla.redhat.com/show_bug.cgi?id=772720
2012-01-14
Published