Уязвимость CVE-2007-4771: Информация

Описание

Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack. NOTE: some of these details are obtained from third party information.

Важность: CRITICAL (9,3)

Опубликовано: 29 января 2008 г.
Изменено: 16 октября 2018 г.
Идентификатор типа ошибки: CWE-399

Ссылки на рекомендации, решения и инструменты

Ссылка
Ресурс
[icu-support] 20080122 ICU Patch for bugs in Regular Expressions
  • Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=429025
  • Issue Tracking
  • Third Party Advisory
MDVSA-2008:026
  • Broken Link
RHSA-2008:0090
  • Third Party Advisory
27455
  • Patch
  • Third Party Advisory
  • VDB Entry
1019269
  • Third Party Advisory
  • VDB Entry
28575
  • Permissions Required
28615
  • Permissions Required
FEDORA-2008-1036
  • Third Party Advisory
FEDORA-2008-1076
  • Third Party Advisory
28669
  • Permissions Required
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0043
  • Third Party Advisory
https://issues.rpath.com/browse/RPL-2199
  • Third Party Advisory
28783
  • Permissions Required
DSA-1511
  • Third Party Advisory
SUSE-SR:2008:005
  • Third Party Advisory
29194
  • Permissions Required
29242
  • Permissions Required
233922
  • Broken Link
29291
  • Permissions Required
GLSA-200803-20
  • Third Party Advisory
29333
  • Permissions Required
USN-591-1
  • Third Party Advisory
29294
  • Permissions Required
http://www.openoffice.org/security/cves/CVE-2007-4770.html
  • Third Party Advisory
http://www.openoffice.org/security/cves/CVE-2007-5745.html
  • Third Party Advisory
231641
  • Broken Link
SUSE-SA:2008:023
  • Third Party Advisory
29852
  • Permissions Required
29910
  • Permissions Required
29987
  • Permissions Required
GLSA-200805-16
  • Third Party Advisory
30179
  • Permissions Required
ADV-2008-0807
  • Third Party Advisory
ADV-2008-1375
  • Third Party Advisory
ADV-2008-0282
  • Third Party Advisory
libicu-dointerval-bo(39936)
  • Third Party Advisory
  • VDB Entry
oval:org.mitre.oval:def:5431
  • Third Party Advisory
oval:org.mitre.oval:def:10507
  • Third Party Advisory
20080206 rPSA-2008-0043-1 icu
      1. Конфигурация 1

        cpe:2.3:a:icu-project:international_components_for_unicode:*:*:*:*:*:c\/c\+\+:*:*
        End including
        3.8.1