CVE-2007-6067: Medium severity PostgreSQL postgresql vulnerability
Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6067?
CVE-2007-6067 has a Medium severity level due to its potential to cause denial of service through memory consumption.
How do I fix CVE-2007-6067?
To fix CVE-2007-6067, upgrade to PostgreSQL version 8.2.6 or later, or Tcl version 8.4.17 or later.
Which software is affected by CVE-2007-6067?
CVE-2007-6067 affects various versions of PostgreSQL prior to 8.2.6 and Tcl versions up to 8.4.16.
What type of vulnerability is CVE-2007-6067?
CVE-2007-6067 is an algorithmic complexity vulnerability in the regular expression parser.
Can CVE-2007-6067 be exploited remotely?
Yes, CVE-2007-6067 can be exploited by remote authenticated users to trigger a denial of service.