Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2007-6067

Опубликовано: 07 янв. 2008
Источник: redhat
CVSS2: 1.5

Описание

Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 4tclWill not fix
Red Hat Enterprise Linux 4postgresqlFixedRHSA-2008:003811.01.2008
Red Hat Enterprise Linux 5postgresqlFixedRHSA-2008:003811.01.2008
Red Hat Enterprise Linux 5tclFixedRHSA-2013:012208.01.2013
Red Hat Web Application Stack for RHEL 4postgresqlFixedRHSA-2008:004001.02.2008

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=400931postgresql: tempory DoS caused by slow regex NFA cleanup

1.5 Low

CVSS2

Связанные уязвимости

ubuntu
больше 17 лет назад

Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.

nvd
больше 17 лет назад

Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.

debian
больше 17 лет назад

Algorithmic complexity vulnerability in the regular expression parser ...

github
около 3 лет назад

Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.

oracle-oval
больше 12 лет назад

ELSA-2013-0122: tcl security and bug fix update (MODERATE)

1.5 Low

CVSS2