UBUNTU-CVE-2012-0039

    Dashboard / Vulnerabilities / UBUNTU-CVE-2012-0039

    UBUNTU-CVE-2012-0039

    Published: 14 Jan 2012Last Modified: 22 Apr 2026
    Upstream:

    Summary:

    Details: GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.

    Affected packages

    Package

    Name: glib2.0

    Purl: pkg:deb/ubuntu/[email protected]+esm7?arch=source&distro=esm-infra-legacy/trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    2.38.0-1ubuntu1
    2.38.1-1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High