4

CVE-2007-4772

Exploit

The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.

Data is provided by the National Vulnerability Database (NVD)
PostgresqlPostgresql Version >= 7.4 < 7.4.19
PostgresqlPostgresql Version >= 8.0 < 8.0.15
PostgresqlPostgresql Version >= 8.1 < 8.1.11
PostgresqlPostgresql Version >= 8.2 < 8.2.6
DebianDebian Linux Version3.1
CanonicalUbuntu Linux Version6.06 SwEditionlts
CanonicalUbuntu Linux Version6.10
CanonicalUbuntu Linux Version7.04
CanonicalUbuntu Linux Version7.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.93% 0.754
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
https://usn.ubuntu.com/568-1/
Third Party Advisory
http://securitytracker.com/id?1019157
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/27163
Patch
Third Party Advisory
VDB Entry