CVE-2007-4769
Last modified
CVE-2007-4769 is a vulnerability of currently unknown severity. The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.. EPSS estimates a 3.64% chance of exploitation in the next 30 days.
Description
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (backend crash) via an out-of-bounds backref number.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | 7.3 |
| Postgresql | Postgresql | 7.3.1 |
| Postgresql | Postgresql | 7.3.2 |
| Postgresql | Postgresql | 7.3.3 |
| Postgresql | Postgresql | 7.3.4 |
| Postgresql | Postgresql | 7.3.6 |
| Postgresql | Postgresql | 7.3.8 |
| Postgresql | Postgresql | 7.3.9 |
| Postgresql | Postgresql | 7.3.10 |
| Postgresql | Postgresql | 7.3.11 |
| Postgresql | Postgresql | 7.3.12 |
| Postgresql | Postgresql | 7.3.13 |
| Postgresql | Postgresql | 7.3.14 |
| Postgresql | Postgresql | 7.3.15 |
| Postgresql | Postgresql | 7.3.16 |
| Postgresql | Postgresql | 7.3.19 |
| Postgresql | Postgresql | 7.4 |
| Postgresql | Postgresql | 7.4.1 |
| Postgresql | Postgresql | 7.4.2 |
| Postgresql | Postgresql | 7.4.3 |
| Postgresql | Postgresql | 7.4.4 |
| Postgresql | Postgresql | 7.4.5 |
| Postgresql | Postgresql | 7.4.6 |
| Postgresql | Postgresql | 7.4.7 |
| Postgresql | Postgresql | 7.4.8 |
| Postgresql | Postgresql | 7.4.9 |
| Postgresql | Postgresql | 7.4.10 |
| Postgresql | Postgresql | 7.4.11 |
| Postgresql | Postgresql | 7.4.12 |
| Postgresql | Postgresql | 7.4.13 |
| Postgresql | Postgresql | 7.4.14 |
| Postgresql | Postgresql | 7.4.16 |
| Postgresql | Postgresql | 7.4.17 |
| Postgresql | Postgresql | 8.0 |
| Postgresql | Postgresql | 8.0.1 |
| Postgresql | Postgresql | 8.0.2 |
| Postgresql | Postgresql | 8.0.3 |
| Postgresql | Postgresql | 8.0.4 |
| Postgresql | Postgresql | 8.0.5 |
| Postgresql | Postgresql | 8.0.7 |
| Postgresql | Postgresql | 8.0.8 |
| Postgresql | Postgresql | 8.0.9 |
| Postgresql | Postgresql | 8.0.11 |
| Postgresql | Postgresql | 8.0.13 |
| Postgresql | Postgresql | 8.0.317 |
| Postgresql | Postgresql | 8.1.1 |
| Postgresql | Postgresql | 8.1.3 |
| Postgresql | Postgresql | 8.1.4 |
| Postgresql | Postgresql | 8.1.5 |
| Postgresql | Postgresql | 8.1.7 |
Showing 50 of 57 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/28359Vendor Advisory
- http://secunia.com/advisories/28376Vendor Advisory
- http://secunia.com/advisories/28437Vendor Advisory
- http://secunia.com/advisories/28438Vendor Advisory
- http://secunia.com/advisories/28454Vendor Advisory
- http://secunia.com/advisories/28455Vendor Advisory
- http://secunia.com/advisories/28464Vendor Advisory
- http://secunia.com/advisories/28479Vendor Advisory
- http://secunia.com/advisories/28679Vendor Advisory
- http://secunia.com/advisories/28698Vendor Advisory
- http://secunia.com/advisories/29638Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0061Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0109Vendor Advisory
- http://secunia.com/advisories/28359Vendor Advisory
- http://secunia.com/advisories/28376Vendor Advisory
- http://secunia.com/advisories/28437Vendor Advisory
- http://secunia.com/advisories/28438Vendor Advisory
- http://secunia.com/advisories/28454Vendor Advisory
- http://secunia.com/advisories/28455Vendor Advisory
- http://secunia.com/advisories/28464Vendor Advisory
- http://secunia.com/advisories/28479Vendor Advisory
- http://secunia.com/advisories/28679Vendor Advisory
- http://secunia.com/advisories/28698Vendor Advisory
- http://secunia.com/advisories/29638Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0061Vendor Advisory
- http://www.vupen.com/english/advisories/2008/0109Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4769?
How severe is CVE-2007-4769?
How do I fix CVE-2007-4769?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4762Multiple SQL injection vulnerabilities in embadmin/login.asp…
- CVE-2007-4763PHP remote file inclusion vulnerability in dbmodules/DB_adod…
- CVE-2007-4764Directory traversal vulnerability in pawfaliki.php in Pawfal…
- CVE-2007-4766Multiple integer overflows in Perl-Compatible Regular Expres…
- CVE-2007-4767Perl-Compatible Regular Expression (PCRE) library before 7.3…
- CVE-2007-4768Heap-based buffer overflow in Perl-Compatible Regular Expres…
- CVE-2007-4770libicu in International Components for Unicode (ICU) 3.8.1 a…
- CVE-2007-4771Heap-based buffer overflow in the doInterval function in reg…
- CVE-2007-4772The regular expression parser in TCL before 8.4.17, as used …
- CVE-2007-4773Systrace before 1.6.0 has insufficient escape policy enforce…9.8
- CVE-2007-4774The Linux kernel before 2.4.36-rc1 has a race condition. It …5.9
- CVE-2007-4776Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise…
Are you affected by CVE-2007-4769?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
