Vulnerability Name:

CVE-2008-0171 (CCN-39748)

Assigned:2008-01-11
Published:2008-01-11
Updated:2018-10-15
Summary:regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.6 Medium (REDHAT CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
3.4 Low (REDHAT Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: CONFIRM
Type: UNKNOWN
http://bugs.gentoo.org/show_bug.cgi?id=205955

Source: MITRE
Type: CNA
CVE-2008-0171

Source: MITRE
Type: CNA
CVE-2008-0172

Source: SUSE
Type: UNKNOWN
SUSE-SR:2008:006

Source: CCN
Type: RHSA-2012-0305
Low: boost security and bug fix update

Source: CCN
Type: SA28511
Boost Regular Expressions Denial of Service Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
28511

Source: SECUNIA
Type: UNKNOWN
28527

Source: SECUNIA
Type: UNKNOWN
28545

Source: SECUNIA
Type: UNKNOWN
28705

Source: SECUNIA
Type: UNKNOWN
28860

Source: SECUNIA
Type: UNKNOWN
28943

Source: SECUNIA
Type: UNKNOWN
29323

Source: CCN
Type: SA41846
Attachmate Reflection for Secure IT Boost Library Denial of Service

Source: SECUNIA
Type: UNKNOWN
48099

Source: CCN
Type: boost Web site
Changeset 42674 - Boost C++ Libraries - Trac

Source: CONFIRM
Type: Exploit
http://svn.boost.org/trac/boost/changeset/42674

Source: CONFIRM
Type: Exploit
http://svn.boost.org/trac/boost/changeset/42745

Source: CONFIRM
Type: UNKNOWN
http://wiki.rpath.com/Advisories:rPSA-2008-0063

Source: CCN
Type: GLSA-200802-08
Boost: Denial of Service

Source: GENTOO
Type: UNKNOWN
GLSA-200802-08

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2008:032

Source: CCN
Type: OSVDB ID: 42790
Boost Regex Library (Boost.Regex) regex/v4/perl_matcher_non_recursive.hpp Invalid RegExp DoS

Source: CCN
Type: OSVDB ID: 42791
Boost Regex Library (Boost.Regex) basic_regex_creator.hpp get_repeat_type Function DoS

Source: BUGTRAQ
Type: UNKNOWN
20080213 rPSA-2008-0063-1 boost

Source: BID
Type: UNKNOWN
27325

Source: CCN
Type: BID-27325
Boost Library Regular Expression Remote Denial of Service Vulnerabilities

Source: CCN
Type: USN-570-1
boost vulnerabilities

Source: UBUNTU
Type: UNKNOWN
USN-570-1

Source: VUPEN
Type: UNKNOWN
ADV-2008-0249

Source: XF
Type: UNKNOWN
boost-basicregexparser-dos(39748)

Source: CONFIRM
Type: UNKNOWN
https://issues.rpath.com/browse/RPL-2143

Source: FEDORA
Type: UNKNOWN
FEDORA-2008-0880

Source: SUSE
Type: SUSE-SR:2008:006
SUSE Security Summary Report

Vulnerable Configuration:Configuration 1:
  • cpe:/a:boost:boost:1.33:*:*:*:*:*:*:*
  • OR cpe:/a:boost:boost:1.34:*:*:*:*:*:*:*
  • OR cpe:/a:boost:boost_regex_library:*:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:5:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:5::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:5::client_workstation:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:5::server:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20080171
    V
    CVE-2008-0171
    2022-09-02
    oval:org.opensuse.security:def:42278
    P
    Security update for libvirt (Moderate)
    2022-05-05
    oval:org.opensuse.security:def:26221
    P
    Security update for python-numpy (Moderate) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:31752
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:33058
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:31710
    P
    Security update for java-1_7_0-openjdk (Important)
    2021-11-24
    oval:org.opensuse.security:def:32227
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:31705
    P
    Security update for postgresql, postgresql13, postgresql14 (Important)
    2021-11-20
    oval:org.opensuse.security:def:31305
    P
    Security update for the Linux Kernel (Live Patch 39 for SLE 12 SP3) (Important)
    2021-11-19
    oval:org.opensuse.security:def:26153
    P
    Security update for git (Low)
    2021-10-20
    oval:org.opensuse.security:def:33019
    P
    Security update for apache2 (Important)
    2021-10-06
    oval:org.opensuse.security:def:26139
    P
    Security update for libvirt (Moderate)
    2021-10-04
    oval:org.opensuse.security:def:105573
    P
    boinc-client-7.18.0-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:26132
    P
    Security update for MozillaFirefox (Important)
    2021-09-22
    oval:org.opensuse.security:def:32171
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-08-25
    oval:org.opensuse.security:def:26100
    P
    Security update for djvulibre (Important)
    2021-08-05
    oval:org.opensuse.security:def:31661
    P
    Security update for webkit2gtk3 (Important)
    2021-08-03
    oval:org.opensuse.security:def:32158
    P
    Security update for dbus-1 (Important)
    2021-08-02
    oval:org.opensuse.security:def:31228
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP3) (Important)
    2021-07-21
    oval:org.opensuse.security:def:31647
    P
    Security update for libgcrypt (Important)
    2021-06-24
    oval:org.opensuse.security:def:31648
    P
    Security update for openexr (Important)
    2021-06-24
    oval:org.opensuse.security:def:31213
    P
    Security update for libnettle (Important)
    2021-06-23
    oval:org.opensuse.security:def:36379
    P
    boost-devel-1.36.0-12.6.49 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42502
    P
    boost-license-1.36.0-12.6.49 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26070
    P
    Security update for spice (Important)
    2021-06-08
    oval:org.opensuse.security:def:36095
    P
    boost-license-1.36.0-12.6.49 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:42081
    P
    Security update for polkit (Important)
    2021-06-03
    oval:org.opensuse.security:def:26051
    P
    Security update for djvulibre (Important)
    2021-05-19
    oval:org.opensuse.security:def:32092
    P
    Security update for the Linux Kernel (Important)
    2021-05-18
    oval:org.opensuse.security:def:31154
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:31605
    P
    Security update for xorg-x11-server (Important)
    2021-04-14
    oval:org.opensuse.security:def:31142
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:31143
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-04-07
    oval:org.opensuse.security:def:31749
    P
    Security update for MozillaFirefox (Important)
    2021-03-31
    oval:org.opensuse.security:def:26213
    P
    Security update for evolution-data-server (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:31360
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:32276
    P
    Security update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:31362
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:31350
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:26197
    P
    Security update for postgresql13 (Moderate)
    2021-02-22
    oval:org.opensuse.security:def:31339
    P
    Security update for the Linux Kernel (Important)
    2021-02-12
    oval:org.opensuse.security:def:31338
    P
    Security update for openvswitch (Important)
    2021-02-12
    oval:org.opensuse.security:def:32114
    P
    Security update for java-1_7_1-ibm (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:32835
    P
    Security update for MozillaFirefox (Critical)
    2020-12-21
    oval:org.opensuse.security:def:32015
    P
    Security update for openssl (Important)
    2020-12-11
    oval:org.opensuse.security:def:31562
    P
    Security update for xen (Important)
    2020-12-07
    oval:org.opensuse.security:def:31561
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:32004
    P
    Security update for postgresql12 (Important)
    2020-12-04
    oval:org.opensuse.security:def:35527
    P
    boost-license-1.36.0-11.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35674
    P
    boost-license-1.36.0-11.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:41934
    P
    boost-license-1.36.0-11.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35871
    P
    boost-license-1.36.0-12.3.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:31081
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:25708
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31771
    P
    Security update for MozillaFirefox, MozillaFirefox-branding-SLED, firefox-gcc5, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:25079
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:25998
    P
    Security update for libreoffice (Important)
    2020-12-01
    oval:org.opensuse.security:def:27093
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25421
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:31424
    P
    Security update for php53 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26354
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25796
    P
    Security update for util-linux (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32453
    P
    Security update for xfsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25154
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31509
    P
    Security update for python27 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25433
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:31871
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:26558
    P
    gnutls on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25854
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25929
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25363
    P
    Security update for samba (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25625
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26646
    P
    unzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26527
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26004
    P
    Security update for shotwell (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25651
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:31857
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:26835
    P
    unrar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25986
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26704
    P
    g3utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25855
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:31918
    P
    Security update for gd (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25226
    P
    Security update for e2fsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32315
    P
    Security update for rsync (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27377
    P
    boost-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25644
    P
    Security update for taglib (Low)
    2020-12-01
    oval:org.opensuse.security:def:31449
    P
    Security update for postgresql10 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25943
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32600
    P
    quagga on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25301
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26323
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:32381
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25656
    P
    Security update for spice-gtk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25420
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26001
    P
    Security update for openexr (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30996
    P
    Security update for jasper (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25510
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:31948
    P
    Security update for gpg2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26376
    P
    Security update for MozillaThunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25848
    P
    Security update for flex, at, bogofilter, cyrus-imapd, kdelibs4, libQtWebKit4, libbonobo, mdbtools, netpbm, openslp, sgmltool, virtuoso, libqt5-qtwebkit (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25655
    P
    Security update for spice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26674
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25078
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:25847
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:32053
    P
    Security update for kvm (Important)
    2020-12-01
    oval:org.opensuse.security:def:27058
    P
    xorg-x11 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26270
    P
    Security update for mariadb-100 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25757
    P
    Security update for flash-player (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31815
    P
    Security update for apache2-mod_perl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25090
    P
    Security update for git (Important)
    2020-12-01
    oval:org.opensuse.security:def:31452
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25422
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:31556
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:26505
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25810
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32492
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25928
    P
    Security update for pcre (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25282
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:31596
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32796
    P
    tar on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25497
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:31928
    P
    Security update for giflib (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26607
    P
    libvorbis on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26492
    P
    Security update for icingaweb2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25940
    P
    Security update for mariadb (Important)
    2020-12-01
    oval:org.opensuse.security:def:25567
    P
    Security update for java-11-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:31808
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25706
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26660
    P
    NetworkManager-gnome on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25802
    P
    Recommended update for LibreOffice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31896
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26870
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25225
    P
    Security update for systemd (Important)
    2020-12-01
    oval:org.opensuse.security:def:27342
    P
    zoo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31573
    P
    Security update for strongswan (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25904
    P
    Security update for gegl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31962
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25237
    P
    Security update for libvpx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26274
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32337
    P
    Security update for sblim-sfcb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25645
    P
    Security update for the Linux Kernel (Critical)
    2020-12-01
    oval:org.opensuse.security:def:31779
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25957
    P
    Security update for webkit2gtk3 (Important)
    2020-12-01
    oval:org.opensuse.security:def:32639
    P
    boost-license on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30995
    P
    Security update for jasper (Important)
    2020-12-01
    oval:org.opensuse.security:def:25429
    P
    Security update for libzypp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31792
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:26362
    P
    Security update for nginx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25720
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:25504
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:26639
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31007
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:25763
    P
    Security Update for Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26420
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:27436
    P
    ELSA-2012-0305 -- boost security and bug fix update (low)
    2014-12-15
    oval:org.mitre.oval:def:27054
    P
    RHSA-2012:0305 -- boost security and bug fix update (Low)
    2014-12-08
    oval:org.mitre.oval:def:17492
    P
    USN-570-1 -- boost vulnerabilities
    2014-06-30
    oval:com.redhat.rhsa:def:20120305
    P
    RHSA-2012:0305: boost security and bug fix update (Low)
    2012-02-21
    BACK
    boost boost 1.33
    boost boost 1.34
    boost boost regex library *