CVE-2012-0840
EPSS 40.2%
Description
tables/apr_hash.c in the Apache Portable Runtime (APR) library through 1.4.5 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.
How to fix CVE-2012-0840
To remediate CVE-2012-0840, upgrade the affected package to a fixed version below.
- Debian/apr—upgrade to 1.4.6-1 or later
Is CVE-2012-0840 being exploited?
Moderate — EPSS is 40.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.4.6-1