First published: Wed Jan 16 2008(Updated: )
Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/3.8 | <5. | 5. |
ICU (International Components for Unicode) | <=3.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4771 has a high severity rating due to its potential to cause memory consumption and denial of service.
To mitigate CVE-2007-4771, upgrade to libicu version 5.0 or later.
ICU versions 3.8.1 and earlier are affected by CVE-2007-4771.
While CVE-2007-4771 primarily causes denial of service, it may also lead to unspecified other impacts, including potential data breaches.
CVE-2007-4771 is less of a concern for modern systems that have been updated to versions beyond 5.0.