Vulnerabilities > CVE-2021-37606 - Information Exposure Through Discrepancy vulnerability in Meow Hash Project Meow Hash 0.5
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE Summary
Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision in the bottom bits of the hashes of two messages, as demonstrated by an attack against a long-running web service that allows the attacker to infer collisions by measuring timing differences.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |