CVE-2011-4967: Input Validation
Published Nov 19, 2019
·Updated
tog-Pegasus has a package hash collision DoS vulnerability
Affected Software
4 affected components
OpenPegasus Tog-pegasus<2.12
redhat Enterprise Linux=4.0
redhat Enterprise Linux=5.0
redhat Enterprise Linux=6.0
Remediation
Patch Available
Event History
Nov 19, 2019
CVE Published
via MITRE·03:10 PM
Data Sourced
via MITRE·03:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2011-4967?
The severity of CVE-2011-4967 is classified as a Denial of Service (DoS) vulnerability due to a package hash collision.
2
How do I fix CVE-2011-4967?
To fix CVE-2011-4967, update to the latest version of Tog-Pegasus or apply relevant patches provided by your operating system vendor.
3
What software is affected by CVE-2011-4967?
CVE-2011-4967 affects Tog-Pegasus versions prior to 2.12, as well as Red Hat Enterprise Linux 4.0, 5.0, and 6.0.
4
What impacts can CVE-2011-4967 have on my system?
CVE-2011-4967 can lead to service interruptions due to denial of service, impacting the availability of the affected software.
5
Is there a workaround for CVE-2011-4967?
A potential workaround for CVE-2011-4967 may involve monitoring and limiting the use of package hashing features until the vulnerability can be mitigated.