CVE-2007-4772
Last modified
CVE-2007-4772 is a vulnerability of currently unknown severity. The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.. EPSS estimates a 3.84% chance of exploitation in the next 30 days.
Description
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | >= 7.4, < 7.4.19 |
| Postgresql | Postgresql | >= 8.0, < 8.0.15 |
| Postgresql | Postgresql | >= 8.1, < 8.1.11 |
| Postgresql | Postgresql | >= 8.2, < 8.2.6 |
| Tcl | Tcl\/Tk | < 8.4.17 |
| Debian | Debian Linux | 3.1 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 6.10 |
| Canonical | Ubuntu Linux | 7.04 |
| Canonical | Ubuntu Linux | 7.10 |
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0122.htmlThird Party Advisory
- http://secunia.com/advisories/28359Third Party Advisory
- http://secunia.com/advisories/28376Third Party Advisory
- http://secunia.com/advisories/28437Third Party Advisory
- http://secunia.com/advisories/28438Third Party Advisory
- http://secunia.com/advisories/28454Third Party Advisory
- http://secunia.com/advisories/28455Third Party Advisory
- http://secunia.com/advisories/28464Third Party Advisory
- http://secunia.com/advisories/28477Third Party Advisory
- http://secunia.com/advisories/28479Third Party Advisory
- http://secunia.com/advisories/28679Third Party Advisory
- http://secunia.com/advisories/28698Third Party Advisory
- http://secunia.com/advisories/29070Third Party Advisory
- http://secunia.com/advisories/29248Third Party Advisory
- http://secunia.com/advisories/29638Third Party Advisory
- http://secunia.com/advisories/30535Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://securitytracker.com/id?1019157Third Party Advisory, VDB Entry
- http://sourceforge.net/project/shownotes.php?release_id=565440&group_id=10894Third Party Advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=1810264&group_id=10894&atid=110894Exploit, Third Party Advisory
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:004Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:059Third Party Advisory
- http://www.postgresql.org/about/news.905Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0134.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/485864/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/486407/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/493080/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27163Patch, Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2008/0061Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0109Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1071/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39497Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1768Broken Link
- https://usn.ubuntu.com/568-1/Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0122.htmlThird Party Advisory
- http://secunia.com/advisories/28359Third Party Advisory
- http://secunia.com/advisories/28376Third Party Advisory
- http://secunia.com/advisories/28437Third Party Advisory
- http://secunia.com/advisories/28438Third Party Advisory
- http://secunia.com/advisories/28454Third Party Advisory
- http://secunia.com/advisories/28455Third Party Advisory
- http://secunia.com/advisories/28464Third Party Advisory
- http://secunia.com/advisories/28477Third Party Advisory
- http://secunia.com/advisories/28479Third Party Advisory
- http://secunia.com/advisories/28679Third Party Advisory
- http://secunia.com/advisories/28698Third Party Advisory
- http://secunia.com/advisories/29070Third Party Advisory
- http://secunia.com/advisories/29248Third Party Advisory
- http://secunia.com/advisories/29638Third Party Advisory
- http://secunia.com/advisories/30535Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://securitytracker.com/id?1019157Third Party Advisory, VDB Entry
- http://sourceforge.net/project/shownotes.php?release_id=565440&group_id=10894Third Party Advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=1810264&group_id=10894&atid=110894Exploit, Third Party Advisory
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:004Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:059Third Party Advisory
- http://www.postgresql.org/about/news.905Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0134.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/485864/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/486407/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/493080/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27163Patch, Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2008/0061Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0109Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1071/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39497Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1768Broken Link
- https://usn.ubuntu.com/568-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4772?
How severe is CVE-2007-4772?
How do I fix CVE-2007-4772?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-4766Multiple integer overflows in Perl-Compatible Regular Expres…
- CVE-2007-4767Perl-Compatible Regular Expression (PCRE) library before 7.3…
- CVE-2007-4768Heap-based buffer overflow in Perl-Compatible Regular Expres…
- CVE-2007-4769The regular expression parser in TCL before 8.4.17, as used …
- CVE-2007-4770libicu in International Components for Unicode (ICU) 3.8.1 a…
- CVE-2007-4771Heap-based buffer overflow in the doInterval function in reg…
- CVE-2007-4773Systrace before 1.6.0 has insufficient escape policy enforce…9.8
- CVE-2007-4774The Linux kernel before 2.4.36-rc1 has a race condition. It …5.9
- CVE-2007-4776Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise…
- CVE-2007-4777SQL injection vulnerability in Joomla! 1.5 before RC2 (aka E…
- CVE-2007-4778Multiple SQL injection vulnerabilities in the content compon…
- CVE-2007-4779Cross-site scripting (XSS) vulnerability in Joomla! 1.5 befo…
Are you affected by CVE-2007-4772?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
