oss-sec mailing list archives
CVE-2017-11343 CHICKEN Scheme: algorithmic complexity attack in hash tables
From: Peter Bex <peter () more-magic net>
Date: Mon, 17 Jul 2017 08:51:29 +0200
Hi all, I just received the CVE-2017-11343 assignment for an issue in CHICKEN Scheme. An attacker is able to cause O(n) lookup for hash tables by predicting the buckets in which interned symbols will end up, due to a partially incorrect fix for CVE-2012-6125 where the randomization factor was determined before initializing the PRNG with a seed state. This issue affects only the Scheme symbol table, not user-created hash tables. All CHICKEN releases up to and including 4.12.0 are affected. More info: http://lists.nongnu.org/archive/html/chicken-announce/2017-07/msg00000.html Cheers, Peter Bex
Attachment:
signature.asc
Description:
Current thread:
- CVE-2017-11343 CHICKEN Scheme: algorithmic complexity attack in hash tables Peter Bex (Jul 16)