Boost Library Regular Expression Remote Denial of Service Vulnerabilities
BID:27325
Info
Boost Library Regular Expression Remote Denial of Service Vulnerabilities
| Bugtraq ID: | 27325 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0171 CVE-2008-0172 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 16 2008 12:00AM |
| Updated: | Mar 19 2015 08:13AM |
| Credit: | Will Drewry and Tavis Ormandy are credited with discovering this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.10 sparc Ubuntu Ubuntu Linux 7.10 powerpc Ubuntu Ubuntu Linux 7.10 i386 Ubuntu Ubuntu Linux 7.10 amd64 Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 SuSE SUSE Linux Enterprise Server 10 SuSE SUSE Linux Enterprise Desktop 10 SuSE openSUSE 10.3 S.u.S.E. openSUSE 10.2 S.u.S.E. Linux 10.1 x86-64 S.u.S.E. Linux 10.1 x86 S.u.S.E. Linux 10.1 ppc rPath rPath Linux 1 RedHat Enterprise Linux Desktop Workstation 5 client Red Hat Fedora 7 Red Hat Enterprise Linux Desktop 5 client Red Hat Enterprise Linux 5 Server Oracle Enterprise Linux 5 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 Gentoo Linux Boost Boost 1.34.1 Boost Boost 1.33.1 Avaya IP Office Application Server 8.0 Avaya IP Office Application Server 7.0 Avaya IP Office Application Server 6.1 Avaya IP Office Application Server 6.0 Avaya Aura Session Manager 6.1.3 Avaya Aura Session Manager 6.1.2 Avaya Aura Session Manager 6.1.1 Avaya Aura Session Manager 6.1 SP2 Avaya Aura Session Manager 6.1 Sp1 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Session Manager 1.0 Attachmate Reflection for Secure IT 7.1 Attachmate Reflection for Secure IT 7.0 |
| Not Vulnerable: |
Attachmate Reflection for Secure IT 7.2 |
Discussion
Boost Library Regular Expression Remote Denial of Service Vulnerabilities
The Boost library is prone to a remote denial-of-service vulnerability because it fails to adequately verify user-supplied input on regular expressions.
Successful exploits may allow remote attackers to cause denial-of-service conditions on applications that use the affected library.
This issue affects Boost 1.33.1 and 1.34.1; other versions may also be affected.
The Boost library is prone to a remote denial-of-service vulnerability because it fails to adequately verify user-supplied input on regular expressions.
Successful exploits may allow remote attackers to cause denial-of-service conditions on applications that use the affected library.
This issue affects Boost 1.33.1 and 1.34.1; other versions may also be affected.
Exploit / POC
Boost Library Regular Expression Remote Denial of Service Vulnerabilities
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Boost Library Regular Expression Remote Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Boost Library Regular Expression Remote Denial of Service Vulnerabilities
References:
References:
- Boost Homepage (Boost)
- boost security and bug fix update (RHSA-2012-0305) (Avaya)
- Security Updates and Reflection for Secure IT 7.x (Attachmate)
- GLSA 200802-08: Boost: Denial of Service (Gentoo)