Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2007-4767

Overview

Vulnerability Score 5.0 5.0
CVE Id CVE-2007-4767
Last Modified 07 Mar 2011 09:59:09
Published 07 Nov 2007 06:46:00
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact PARTIAL PARTIAL
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2007-4767

Summary

Perl-Compatible Regular Expression (PCRE) library before 7.3 does not properly compute the length of (1) a \p sequence, (2) a \P sequence, or (3) a \P{x} sequence, which allows context-dependent attackers to cause a denial of service (infinite loop or crash) or execute arbitrary code.

Vulnerable Systems

Application

  • Pcre 6.0

  • Pcre 6.1

  • Pcre 7.3


References

CERT - TA07-352A

VUPEN - ADV-2008-0924

VUPEN - ADV-2007-4238

VUPEN - ADV-2007-3790

VUPEN - ADV-2007-3725

CONFIRM - http://www.pcre.org/changelog.txt

DEBIAN - DSA-1570

DEBIAN - DSA-1399

SECUNIA - 30106

FEDORA - FEDORA-2008-1842

CONFIRM - https://issues.rpath.com/browse/RPL-1738

XF - pcre-p-sequence-bo(38277)

UBUNTU - USN-547-1

BID - 26346

BUGTRAQ - 20071112 FLEA-2007-0064-1 pcre

BUGTRAQ - 20071106 rPSA-2007-0231-1 pcre

SUSE - SUSE-SA:2007:062

MANDRIVA - MDKSA-2007:211

GENTOO - GLSA-200805-11

GENTOO - GLSA-200801-19

GENTOO - GLSA-200801-18

GENTOO - GLSA-200801-02

GENTOO - GLSA-200711-30

SECUNIA - 30219

SECUNIA - 30155

SECUNIA - 29420

SECUNIA - 29267

SECUNIA - 28720

SECUNIA - 28714

SECUNIA - 28414

SECUNIA - 28406

SECUNIA - 28136

SECUNIA - 27773

SECUNIA - 27741

SECUNIA - 27697

SECUNIA - 27554

SECUNIA - 27543

SECUNIA - 27538

MLIST - [gtk-devel-list] 20071107 GLib 2.14.3

APPLE - APPLE-SA-2008-03-18

APPLE - APPLE-SA-2007-12-17

CONFIRM - http://docs.info.apple.com/article.html?artnum=307562

CONFIRM - http://docs.info.apple.com/article.html?artnum=307179

MISC - http://bugs.gentoo.org/show_bug.cgi?id=198976

Related Patches

Apple 2007-12-17 Security Update 2007-009 (10.4.11 PPC)

Apple 2007-12-21 Security Update 2007-009 1.1 (10.4.11 PPC)

Apple 2007-12-21 Security Update 2007-009 1.1 (10.4.11 Universal)

Apple 2008-03-18 Security Update 2008-002 v1.0 Client (Leopard)

Apple 2008-03-26 Security Update 2008-002 v1.1 Server (Leopard) (Rev 2)

Apple 2008-03-26 Security Update 2008-002 v1.1 Client (Leopard) (Rev 2)


Last Updated: 27 May 2016 10:45:58