CVE-2007-6067
Summary
| CVE | CVE-2007-6067 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-01-09 21:46:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
CompleteAV:N/AC:L/Au:S/C:N/I:N/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Postgresql | Postgresql | 7.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.10 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.11 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.12 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.13 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.14 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.15 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.16 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.19 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.8 | All | All | All |
| Application | Postgresql | Postgresql | 7.3.9 | All | All | All |
| Application | Postgresql | Postgresql | 7.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.1 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.10 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.11 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.12 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.13 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.14 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.16 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.17 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.2 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.3 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.4 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.5 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.6 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.7 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.8 | All | All | All |
| Application | Postgresql | Postgresql | 7.4.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.0 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.11 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.13 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.317 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.0.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.1 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.4 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.5 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.7 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.8 | All | All | All |
| Application | Postgresql | Postgresql | 8.1.9 | All | All | All |
| Application | Postgresql | Postgresql | 8.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.2 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.3 | All | All | All |
| Application | Postgresql | Postgresql | 8.2.4 | All | All | All |
| Application | Tcl Tk | Tcl Tk | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Gentoo Linux Documentation -- PostgreSQL: Multiple vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| Support / Security / Advisories / / MDVSA-2008:004 | Mandriva | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| SUSE update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| USN-568-1: PostgreSQL vulnerabilities | Ubuntu security notices | af854a3a-2127-422b-91ae-364da2661108 | usn.ubuntu.com | |
| Tcl / Read-Only Bugs / #3810 O(N^2) compile time for some regexps | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | Exploit |
| SecurityTracker.com Archives - PostgreSQL Bugs Let Remote Authenticated Users Deny Service and Obtain Elevated Privileges | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Mandriva update for postgresql - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Fedora update for postgresql - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian update for postgresql-7.4 - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| PostgreSQL Multiple Privilege Escalation and Denial of Service Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| HP Internet Express for Tru64 UNIX Multiple PostgreSQL Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| PostgreSQL Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Tcl download | SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| [SECURITY] Fedora 8 Update: postgresql-8.2.6-1.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| rPath update for postgresql and postgresql-server - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1460-1 postgresql-8.1 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Red Hat update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| issues.rpath.com/browse/RPL-1768 | af854a3a-2127-422b-91ae-364da2661108 | issues.rpath.com | |
| [security-announce] SUSE Security Announcement: PostgreSQL security issu | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp | af854a3a-2127-422b-91ae-364da2661108 | h20000.www2.hp.com | |
| Sun Solaris 10 PostgreSQL Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Ubuntu update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 7 Update: postgresql-8.2.6-1.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| PostgreSQL: News: 2008-01-07 Cumulative Security Update Release | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Gentoo update for postgresql - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-1463-1 postgresql-7.4 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.