CVE-2012-5373Oracle JDK vulnerability

8 documents6 sources
Severity
5.0MEDIUMNVD
EPSS
0.5%
top 33.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 28
Latest updateMay 17

Description

Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against the MurmurHash3 algorithm, a different vulnerability than CVE-2012-2739.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDoracle/openjdk1.7.0
NVDoracle/jdk1.7.0
NVDoracle/jre1.7.0

🔴Vulnerability Details

3
GHSA
GHSA-3h76-cfv5-34fg: Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability to trigger hash collisions pred2022-05-17
CVEList
CVE-2012-5373: Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability to trigger hash collisions pred2012-11-28
OSV
CVE-2012-5373: Oracle Java SE 7 and earlier, and OpenJDK 7 and earlier, computes hash values without properly restricting the ability to trigger hash collisions pred2012-11-28

📋Vendor Advisories

1
Red Hat
java: Murmur hash function collisions (oCERT-2012-001)2012-11-23

💬Community

3
Bugzilla
CVE-2012-5373 java: Murmur hash function collisions (oCERT-2012-001) [fedora-16]2012-11-27
Bugzilla
CVE-2012-5373 java: Murmur hash function collisions (oCERT-2012-001) [fedora-all]2012-11-27
Bugzilla
CVE-2012-5373 java: Murmur hash function collisions (oCERT-2012-001)2012-11-27
CVE-2012-5373 — Oracle JDK vulnerability | cvebase