Input validation error in Chicken Scheme - CVE-2012-6125
Published: October 31, 2019 / Updated: August 8, 2020
Vulnerability identifier: #VU35127
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-6125
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Chicken before 4.8.0 is susceptible to algorithmic complexity attacks related to hash table collisions.
Affected software
Chicken Scheme
How to mitigate CVE-2012-6125
Install update from vendor's website.
Chicken Scheme - update to 4.8.0
External References
- http://www.openwall.com/lists/oss-security/2013/02/08/2
- https://access.redhat.com/security/cve/cve-2012-6125
- https://lists.nongnu.org/archive/html/chicken-hackers/2012-01/msg00002.html
- https://lists.nongnu.org/archive/html/chicken-hackers/2012-01/msg00020.html
- https://security-tracker.debian.org/tracker/CVE-2012-6125