CVE-2012-0839

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
08/02/2012
Last modified:
11/04/2025

Description

OCaml 3.12.1 and earlier computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:inria:ocaml:*:*:*:*:*:*:*:* 3.12.1 (including)
cpe:2.3:a:inria:ocaml:1.07:*:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:2.02:*:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:2.04:*:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:2.99:alpha:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.00:*:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.01:*:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.02:*:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.03:alpha:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.04:*:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.05:beta:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.06:*:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.07:*:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.07:beta1:*:*:*:*:*:*
cpe:2.3:a:inria:ocaml:3.07:beta2:*:*:*:*:*:*