[Forgot Password]
Login  Register Subscribe

23631

 
 

122183

 
 

98060

 
 

909

 
 

79198

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2007-6067

Date: (C)2008-01-09   (M)2017-11-18 


Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.

CVSS Score: 6.8Access Vector: NETWORK
Exploit Score: 8.0Access Complexity: LOW
Impact Score: 6.9Authentication: SINGLE_INSTANCE
 Confidentiality: NONE
 Integrity: NONE
 Availability: COMPLETE





Reference:
SECTRACK-1019157
SUNALERT-103197
SUNALERT-200559
http://www.securityfocus.com/archive/1/archive/1/485864/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/486407/100/0/threaded
BID-27163
SECUNIA-28359
SECUNIA-28376
SECUNIA-28437
SECUNIA-28438
SECUNIA-28454
SECUNIA-28455
SECUNIA-28464
SECUNIA-28477
SECUNIA-28479
SECUNIA-28679
SECUNIA-28698
SECUNIA-29638
ADV-2008-0061
ADV-2008-0109
ADV-2008-1071
DSA-1460
DSA-1463
FEDORA-2008-0478
FEDORA-2008-0552
GLSA-200801-15
HPSBTU02325
MDVSA-2008:004
RHSA-2008:0038
RHSA-2008:0040
RHSA-2013:0122
SUSE-SA:2008:005
USN-568-1
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://sourceforge.net/project/shownotes.php?release_id=565440&group_id=10894
http://sourceforge.net/tracker/index.php?func=detail&aid=1810264&group_id=10894&atid=110894
http://www.postgresql.org/about/news.905
https://issues.rpath.com/browse/RPL-1768
postgresql-complex-expression-dos(39498)

CPE    40
cpe:/a:postgresql:postgresql:7.3
cpe:/a:postgresql:postgresql:7.4.10
cpe:/a:postgresql:postgresql:7.4.9
cpe:/a:postgresql:postgresql:7.4.11
...
CWE    1
CWE-189
OVAL    6
oval:org.secpod.oval:def:500939
oval:org.secpod.oval:def:202521
oval:org.secpod.oval:def:301295
oval:org.mitre.oval:def:7844
...

© 2013 SecPod Technologies