Release Date: | 2008-01-07 | |
Impact: | Low | What is this? |
Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted complex regular expression with doubly-nested states.
See more information about CVE-2007-6067 from MITRE CVE dictionary and NIST NVD
NOTE: The following CVSS metrics and score provided are preliminary and subject to review.
Base Score: | 1.5 |
Vector String: | AV:L/AC:M/Au:S/C:N/I:N/A:P |
Version: | 2.0 |
Attack Vector: | Local |
Attack Complexity: | Medium |
Authentication: | Single |
Confidentiality Impact: | None |
Integrity Impact: | None |
Availability Impact: | Partial |
Platform | Errata | Release Date |
Oracle Enterprise Linux version 4 (postgresql) | ELSA-2008-0038 | 2008-01-11 |
Oracle Linux version 5 (postgresql) | ELSA-2008-0038 | 2008-01-11 |
Oracle Linux version 5 (tcl) | ELSA-2013-0122 | 2013-01-11 |
This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections: