Vulnerability Description
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | >= 7.4, < 7.4.19 |
| Tcl | Tcl\/Tk | < 8.4.17 |
| Debian | Debian Linux | 3.1 |
| Canonical | Ubuntu Linux | 6.06 |
Related Weaknesses (CWE)
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154Broken Link
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00049.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00052.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00054.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-02/msg00056.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00016.htmlMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0122.htmlThird Party Advisory
- http://secunia.com/advisories/28359Third Party Advisory
- http://secunia.com/advisories/28376Third Party Advisory
- http://secunia.com/advisories/28437Third Party Advisory
- http://secunia.com/advisories/28438Third Party Advisory
- http://secunia.com/advisories/28454Third Party Advisory
- http://secunia.com/advisories/28455Third Party Advisory
FAQ
What is CVE-2007-4772?
CVE-2007-4772 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a d...
How severe is CVE-2007-4772?
CVE-2007-4772 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-4772?
Check the references section above for vendor advisories and patch information. Affected products include: Postgresql Postgresql, Tcl Tcl\/Tk, Debian Debian Linux, Canonical Ubuntu Linux.