Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2007-4772

Опубликовано: 07 янв. 2008
Источник: redhat
CVSS2: 1.5
EPSS Низкий

Описание

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4tclWill not fix
Red Hat Enterprise Linux 2.1tcltkFixedRHSA-2008:013421.02.2008
Red Hat Enterprise Linux 3tcltkFixedRHSA-2008:013421.02.2008
Red Hat Enterprise Linux 4postgresqlFixedRHSA-2008:003811.01.2008
Red Hat Enterprise Linux 5postgresqlFixedRHSA-2008:003811.01.2008
Red Hat Enterprise Linux 5tclFixedRHSA-2013:012208.01.2013
Red Hat Web Application Stack for RHEL 4postgresqlFixedRHSA-2008:004001.02.2008

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=316511postgresql DoS via infinite loop in regex NFA optimization code

EPSS

Процентиль: 77%
0.01069
Низкий

1.5 Low

CVSS2

Связанные уязвимости

ubuntu
больше 17 лет назад

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.

nvd
больше 17 лет назад

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.

debian
больше 17 лет назад

The regular expression parser in TCL before 8.4.17, as used in Postgre ...

github
около 3 лет назад

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.

oracle-oval
больше 12 лет назад

ELSA-2013-0122: tcl security and bug fix update (MODERATE)

EPSS

Процентиль: 77%
0.01069
Низкий

1.5 Low

CVSS2