PT-2008-1536 · Postgresql+3 · Postgresql+3

Published

2008-01-09

·

Updated

2024-07-05

·

CVE-2007-6067

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 8.2.6 PostgreSQL versions prior to 8.1.11 PostgreSQL versions prior to 8.0.15 PostgreSQL versions prior to 7.4.19 TCL versions prior to 8.4.17
Description The issue allows remote authenticated users to cause a denial of service, specifically memory consumption, by providing a crafted complex regular expression with doubly-nested states. This is related to an algorithmic complexity vulnerability in the regular expression parser.
Recommendations For PostgreSQL versions prior to 8.2.6, update to version 8.2.6 or later. For PostgreSQL versions prior to 8.1.11, update to version 8.1.11 or later. For PostgreSQL versions prior to 8.0.15, update to version 8.0.15 or later. For PostgreSQL versions prior to 7.4.19, update to version 7.4.19 or later. For TCL versions prior to 8.4.17, update to version 8.4.17 or later.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1441
ALT-PU-2024-9046
CVE-2007-6067
DSA-1460-1
DSA-1463-1
RHSA-2008:0038
RHSA-2008:0040
RHSA-2008_0038
RHSA-2013:0122
RHSA-2013_0122

Affected Products

Alt Linux
Postgresql
Red Hat
Tcl