CVE-2007-4772: Medium severity PostgreSQL postgresql vulnerability
The regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted regular expression.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-4772?
CVE-2007-4772 is classified as a denial of service vulnerability due to its potential to cause an infinite loop.
How do I fix CVE-2007-4772?
To fix CVE-2007-4772, update to PostgreSQL version 8.2.6 or later, or upgrade Tcl to version 8.4.17 or later.
Which software versions are affected by CVE-2007-4772?
CVE-2007-4772 affects PostgreSQL versions 7.4 prior to 7.4.19, 8.0 prior to 8.0.15, 8.1 prior to 8.1.11, and 8.2 prior to 8.2.6, as well as Tcl before 8.4.17.
Can CVE-2007-4772 be exploited remotely?
Yes, CVE-2007-4772 can be exploited by remote attackers through crafted regular expressions.
What are the potential impacts of CVE-2007-4772?
The potential impacts of CVE-2007-4772 include service outages and degraded performance due to denial of service.