Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table, as demonstrated by a universal multicollision attack against a variant of the MurmurHash2 algorithm, a different vulnerability than CVE-2011-4815.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade ruby | Dec 10, 2025 | Nov 10, 2012 |
| Gentoo Linux | — | Upgrade dev-lang/ruby. | Oct 30, 2017 | Nov 28, 2012 |
| Suse | — | Upgrade ruby19Upgrade ruby19-develUpgrade ruby19-tkUpgrade ruby19-doc-riUpgrade ruby19-devel-extra | Dec 12, 2013 | Nov 28, 2012 |
| Ubuntu | — | Upgrade ruby1.9.1Upgrade libruby1.9.1 | Nov 8, 2024 | Nov 28, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub