CWE-407 算法复杂性

Inefficient Algorithmic Complexity

结构: Simple

Abstraction: Class

状态: Incomplete

被利用可能性: Low

基本描述

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

相关缺陷

  • cwe_Nature: ChildOf cwe_CWE_ID: 405 cwe_View_ID: 1000 cwe_Ordinal: Primary

  • cwe_Nature: ChildOf cwe_CWE_ID: 405 cwe_View_ID: 699 cwe_Ordinal: Primary

适用平台

Language: {'cwe_Class': 'Language-Independent', 'cwe_Prevalence': 'Undetermined'}

常见的影响

范围 影响 注释
Availability ['DoS: Resource Consumption (CPU)', 'DoS: Resource Consumption (Memory)', 'DoS: Resource Consumption (Other)'] The typical consequence is CPU consumption, but memory consumption and consumption of other resources can also occur.

分析过的案例

标识 说明 链接
CVE-2003-0244 CPU consumption via inputs that cause many hash table collisions. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0244
CVE-2003-0364 CPU consumption via inputs that cause many hash table collisions. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0364
CVE-2002-1203 Product performs unnecessary processing before dropping an invalid packet. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1203
CVE-2001-1501 CPU and memory consumption using many wildcards. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1501
CVE-2004-2527 Product allows attackers to cause multiple copies of a program to be loaded more quickly than the program can detect that other copies are running, then exit. This type of error should probably have its own category, where teardown takes more time than initialization. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2527
CVE-2006-6931 Network monitoring system allows remote attackers to cause a denial of service (CPU consumption and detection outage) via crafted network traffic, aka a "backtracking attack." https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6931
CVE-2006-3380 Wiki allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case algorithmic complexity. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3380
CVE-2006-3379 Wiki allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case algorithmic complexity. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3379
CVE-2005-2506 OS allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2506
CVE-2005-1792 Memory leak by performing actions faster than the software can clear them. https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1792

分类映射

映射的分类名 ImNode ID Fit Mapped Node Name
PLOVER Algorithmic Complexity

引用