UBUNTU-CVE-2011-4461
Dashboard / Vulnerabilities / UBUNTU-CVE-2011-4461
UBUNTU-CVE-2011-4461
Summary:
Details: Jetty 8.1.0.RC2 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
References: https://ubuntu.com/security/CVE-2011-4461, http://www.kb.cert.org/vuls/id/903934, http://www.ocert.org/advisories/ocert-2011-003.html, http://www.nruns.com/_downloads/advisory28122011.pdf, http://dev.eclipse.org/mhonarc/lists/jetty-users/msg01818.html, https://ubuntu.com/security/notices/USN-1429-1, https://www.cve.org/CVERecord?id=CVE-2011-4461
Affected packages
Package
Name: jetty
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
