VulnerabilityModified
CVE-2007-4772
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted…
MEDIUM 4.0EPSS 3.81%
Does this matter?
Lower severity and a low EPSS score (3.81%). Track it; it rarely justifies an emergency change on its own.
Description
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.
- CVSS 2.0
- 4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
- EPSS
- 3.81% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-399
- Affected
- postgresql/postgresql · tcl/tcl\/tk · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154Broken Link
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0122.htmlThird Party Advisory
- http://secunia.com/advisories/28359Third Party Advisory
- http://secunia.com/advisories/28376Third Party Advisory
- http://secunia.com/advisories/28437Third Party Advisory
- http://secunia.com/advisories/28438Third Party Advisory
- http://secunia.com/advisories/28454Third Party Advisory
- http://secunia.com/advisories/28455Third Party Advisory
- http://secunia.com/advisories/28464Third Party Advisory
- http://secunia.com/advisories/28477Third Party Advisory
- http://secunia.com/advisories/28479Third Party Advisory
- http://secunia.com/advisories/28679Third Party Advisory
- http://secunia.com/advisories/28698Third Party Advisory
- http://secunia.com/advisories/29070Third Party Advisory
- http://secunia.com/advisories/29248Third Party Advisory
- http://secunia.com/advisories/29638Third Party Advisory
- http://secunia.com/advisories/30535Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200801-15.xmlThird Party Advisory
- http://securitytracker.com/id?1019157Third Party Advisory, VDB Entry
- http://sourceforge.net/project/shownotes.php?release_id=565440&group_id=10894Third Party Advisory
- http://sourceforge.net/tracker/index.php?func=detail&aid=1810264&group_id=10894&atid=110894Exploit, Third Party Advisory
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1Broken Link
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.