2008-01-09 22:46:00 2018-10-15 23:49:32

Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.

Vector

NETWORK

Complexity

LOW

Authentication

SINGLE_INSTANCE

Confidentiality

NONE

Integrity

NONE

Availability

COMPLETE
Postgresql Postgresql 7.3.10 (not an official CPE) Postgresql Postgresql 7.3.11 (not an official CPE) Postgresql Postgresql 7.3.12 (not an official CPE) Postgresql Postgresql 7.3.13 (not an official CPE) Postgresql Postgresql 7.3.14 (not an official CPE) Postgresql Postgresql 7.3.15 (not an official CPE) Postgresql Postgresql 7.3.16 (not an official CPE) Postgresql Postgresql 7.3.19 (not an official CPE) PostgreSQL PostgreSQL 7.4 PostgreSQL PostgreSQL 7.4.1 PostgreSQL PostgreSQL 7.4.2 PostgreSQL PostgreSQL 7.4.3 PostgreSQL PostgreSQL 7.4.4 PostgreSQL PostgreSQL 7.4.5 PostgreSQL PostgreSQL 7.4.6 PostgreSQL PostgreSQL 7.4.7 PostgreSQL PostgreSQL 7.4.8 PostgreSQL PostgreSQL 7.4.9 PostgreSQL PostgreSQL 7.4.10 PostgreSQL PostgreSQL 7.4.11 PostgreSQL PostgreSQL 7.4.12 PostgreSQL PostgreSQL 7.4.13 PostgreSQL PostgreSQL 7.4.14 PostgreSQL PostgreSQL 7.4.16 PostgreSQL PostgreSQL 7.4.17 PostgreSQL 8.0 PostgreSQL PostgreSQL 8.0.1 PostgreSQL PostgreSQL 8.0.2 PostgreSQL PostgreSQL 8.0.3 PostgreSQL PostgreSQL 8.0.4 PostgreSQL PostgreSQL 8.0.5 PostgreSQL PostgreSQL 8.0.7 PostgreSQL PostgreSQL 8.0.8 PostgreSQL PostgreSQL 8.0.9 Tcl tk Tcl tk 8.4.16 (not an official CPE) PostgreSQL 8.2.4 PostgreSQL 8.2.3 PostgreSQL 8.2.2 PostgreSQL 8.2 PostgreSQL 8.1.9 PostgreSQL 8.1.8 PostgreSQL 8.1.7 PostgreSQL 8.1.5 PostgreSQL 8.1.4 PostgreSQL 8.1.3 PostgreSQL 8.1.1 Postgresql Postgresql 8.0.317 (not an official CPE) PostgreSQL PostgreSQL 8.0.13 PostgreSQL PostgreSQL 8.0.11 Postgresql Postgresql 7.3.9 (not an official CPE) Postgresql Postgresql 7.3.8 (not an official CPE) Postgresql Postgresql 7.3.6 (not an official CPE) Postgresql Postgresql 7.3.4 (not an official CPE) Postgresql Postgresql 7.3.3 (not an official CPE) Postgresql Postgresql 7.3.2 (not an official CPE) Postgresql Postgresql 7.3.1 (not an official CPE) PostgreSQL 7.3