CVE-2007-4772
Last modified
CVE-2007-4772 is a vulnerability of currently unknown severity. The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.. EPSS estimates a 3.84% chance of exploitation in the next 30 days.
Description
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | >= 7.4, < 7.4.19 |
| Postgresql | Postgresql | >= 8.0, < 8.0.15 |
| Postgresql | Postgresql | >= 8.1, < 8.1.11 |
| Postgresql | Postgresql | >= 8.2, < 8.2.6 |
| Tcl | Tcl\/Tk | < 8.4.17 |
| Debian | Debian Linux | 3.1 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 6.10 |
| Canonical | Ubuntu Linux | 7.04 |
| Canonical | Ubuntu Linux | 7.10 |
References
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0122.htmlThird Party Advisory
- http://secunia.com/advisories/28359Third Party Advisory
- http://secunia.com/advisories/28376Third Party Advisory
- http://secunia.com/advisories/28437Third Party Advisory
- http://secunia.com/advisories/28438Third Party Advisory
- http://secunia.com/advisories/28454Third Party Advisory
- http://secunia.com/advisories/28455Third Party Advisory
- http://secunia.com/advisories/28464Third Party Advisory
- http://secunia.com/advisories/28477Third Party Advisory
- http://secunia.com/advisories/28479Third Party Advisory
- http://secunia.com/advisories/28679Third Party Advisory
- http://secunia.com/advisories/28698Third Party Advisory
- http://secunia.com/advisories/29070Third Party Advisory
- http://secunia.com/advisories/29248Third Party Advisory
- http://secunia.com/advisories/29638Third Party Advisory
- http://secunia.com/advisories/30535Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://securitytracker.com/id?1019157Third Party Advisory, VDB Entry
- http://sourceforge.net/project/shownotes.php?release_id=565440&group_id=10894Third Party Advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=1810264&group_id=10894&atid=110894Exploit, Third Party Advisory
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:004Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:059Third Party Advisory
- http://www.postgresql.org/about/news.905Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0134.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/485864/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/486407/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/493080/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27163Patch, Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2008/0061Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0109Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1071/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39497Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1768Broken Link
- https://usn.ubuntu.com/568-1/Third Party Advisory
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0122.htmlThird Party Advisory
- http://secunia.com/advisories/28359Third Party Advisory
- http://secunia.com/advisories/28376Third Party Advisory
- http://secunia.com/advisories/28437Third Party Advisory
- http://secunia.com/advisories/28438Third Party Advisory
- http://secunia.com/advisories/28454Third Party Advisory
- http://secunia.com/advisories/28455Third Party Advisory
- http://secunia.com/advisories/28464Third Party Advisory
- http://secunia.com/advisories/28477Third Party Advisory
- http://secunia.com/advisories/28479Third Party Advisory
- http://secunia.com/advisories/28679Third Party Advisory
- http://secunia.com/advisories/28698Third Party Advisory
- http://secunia.com/advisories/29070Third Party Advisory
- http://secunia.com/advisories/29248Third Party Advisory
- http://secunia.com/advisories/29638Third Party Advisory
- http://secunia.com/advisories/30535Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://securitytracker.com/id?1019157Third Party Advisory, VDB Entry
- http://sourceforge.net/project/shownotes.php?release_id=565440&group_id=10894Third Party Advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=1810264&group_id=10894&atid=110894Exploit, Third Party Advisory
- http://www.debian.org/security/2008/dsa-1460Third Party Advisory
- http://www.debian.org/security/2008/dsa-1463Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:004Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:059Third Party Advisory
- http://www.postgresql.org/about/news.905Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0038.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0040.htmlThird Party Advisory
- http://www.redhat.com/support/errata/RHSA-2008-0134.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/485864/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/486407/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/493080/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/27163Patch, Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2008-0009.htmlThird Party Advisory
- http://www.vupen.com/english/advisories/2008/0061Third Party Advisory
- http://www.vupen.com/english/advisories/2008/0109Third Party Advisory
- http://www.vupen.com/english/advisories/2008/1071/referencesThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39497Third Party Advisory, VDB Entry
- https://issues.rpath.com/browse/RPL-1768Broken Link
- https://usn.ubuntu.com/568-1/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4772?
How severe is CVE-2007-4772?
How do I fix CVE-2007-4772?
Are you affected by CVE-2007-4772?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
