CVE Vulnerabilities

CVE-2007-4772

Published: Jan 09, 2008 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:P
RedHat/V2
1.5 MODERATE
AV:L/AC:M/Au:S/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.

Affected Software

Name Vendor Start Version End Version
Postgresql Postgresql 7.4 (including) 7.4.19 (excluding)
Postgresql Postgresql 8.0 (including) 8.0.15 (excluding)
Postgresql Postgresql 8.1 (including) 8.1.11 (excluding)
Postgresql Postgresql 8.2 (including) 8.2.6 (excluding)
Tcl/tk Tcl * 8.4.17 (excluding)
Red Hat Enterprise Linux 2.1 RedHat tcltk-0:8.3.3-75 *
Red Hat Enterprise Linux 3 RedHat tcltk-0:8.3.5-92.8 *
Red Hat Enterprise Linux 4 RedHat postgresql-0:7.4.19-1.el4_6.1 *
Red Hat Enterprise Linux 5 RedHat postgresql-0:8.1.11-1.el5_1.1 *
Red Hat Enterprise Linux 5 RedHat tcl-0:8.4.13-6.el5 *
Red Hat Web Application Stack for RHEL 4 RedHat postgresql-0:8.1.11-1.el4s1.1 *
Postgresql-8.1 Ubuntu dapper *
Postgresql-8.1 Ubuntu edgy *
Postgresql-8.1 Ubuntu feisty *
Postgresql-8.1 Ubuntu gutsy *
Postgresql-8.2 Ubuntu feisty *
Postgresql-8.2 Ubuntu gutsy *
Postgresql-8.2 Ubuntu hardy *
Tcl8.3 Ubuntu dapper *
Tcl8.3 Ubuntu edgy *
Tcl8.3 Ubuntu feisty *
Tcl8.3 Ubuntu gutsy *
Tcl8.3 Ubuntu hardy *
Tcl8.4 Ubuntu dapper *
Tcl8.4 Ubuntu edgy *
Tcl8.4 Ubuntu feisty *
Tcl8.4 Ubuntu gutsy *
Tcl8.4 Ubuntu hardy *

References