CVE-2012-1035: Input Validation
AdaCore Ada Web Services (AWS) before 2.10.2 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1035?
CVE-2012-1035 is classified as a medium severity vulnerability due to its potential for causing denial of service through CPU consumption.
How do I fix CVE-2012-1035?
To fix CVE-2012-1035, upgrade AdaCore Ada Web Services to version 2.10.2 or later.
What type of attack does CVE-2012-1035 enable?
CVE-2012-1035 enables remote denial of service attacks through the exploitation of hash collision vulnerabilities.
Which versions of AdaCore Ada Web Services are affected by CVE-2012-1035?
CVE-2012-1035 affects AdaCore Ada Web Services versions up to and including 2.10.1 and version 2.10.0.
Can CVE-2012-1035 be exploited remotely?
Yes, CVE-2012-1035 can be exploited remotely by attackers sending crafted parameters.