[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2007-4772Date: (C)2008-01-09   (M)2024-02-22


The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.0
Exploit Score: 8.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: NONE
Integrity: NONE
Availability: PARTIAL
  
Reference:
SECTRACK-1019157
SUNALERT-103197
SUNALERT-200559
http://www.securityfocus.com/archive/1/485864/100/0/threaded
http://www.securityfocus.com/archive/1/486407/100/0/threaded
http://www.securityfocus.com/archive/1/493080/100/0/threaded
BID-27163
SECUNIA-28359
SECUNIA-28376
SECUNIA-28437
SECUNIA-28438
SECUNIA-28454
SECUNIA-28455
SECUNIA-28464
SECUNIA-28477
SECUNIA-28479
SECUNIA-28679
SECUNIA-28698
SECUNIA-29070
SECUNIA-29248
SECUNIA-29638
SECUNIA-30535
ADV-2008-0061
ADV-2008-0109
ADV-2008-1071
ADV-2008-1744
DSA-1460
DSA-1463
FEDORA-2008-0478
FEDORA-2008-0552
GLSA-200801-15
MDVSA-2008:004
MDVSA-2008:059
RHSA-2008:0038
RHSA-2008:0040
RHSA-2008:0134
RHSA-2013:0122
SSRT080006
SUSE-SA:2008:005
SUSE-SU-2016:0539
SUSE-SU-2016:0555
SUSE-SU-2016:0677
USN-568-1
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://sourceforge.net/project/shownotes.php?release_id=565440&group_id=10894
http://sourceforge.net/tracker/index.php?func=detail&aid=1810264&group_id=10894&atid=110894
http://www.postgresql.org/about/news.905
http://www.vmware.com/security/advisories/VMSA-2008-0009.html
https://issues.rpath.com/browse/RPL-1768
openSUSE-SU-2016:0531
openSUSE-SU-2016:0578
oval:org.mitre.oval:def:11569
postgresql-regular-expression-dos(39497)

CPE    6
cpe:/a:postgresql:postgresql
cpe:/o:debian:debian_linux:3.1
cpe:/o:canonical:ubuntu_linux:6.06::~~lts~~~
cpe:/o:canonical:ubuntu_linux:7.04
...
CWE    1
CWE-399
OVAL    10
oval:org.secpod.oval:def:89045169
oval:org.secpod.oval:def:400706
oval:org.secpod.oval:def:202521
oval:org.secpod.oval:def:301493
...

© SecPod Technologies