// For flags

CVE-2007-4771

libicu incomplete interval handling

Severity Score

9.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack. NOTE: some of these details are obtained from third party information.

Desbordamiento de búfer basado en montículo en la función doInterval de regexcmp.cpp de libicu de International Components for Unicode (ICU) 3.8.1 y versiones anteriores, permite a atacantes locales o remotos dependientes del contexto provocar una denegación de servicio (agotamiento de memoria) y posiblemente tiene otro impacto desconocido mediante una expresión regular que escribe una gran cantidad de datos en la pila de vuelta atrás (backtracking).
NOTA: algunos de estos detalles se han obtenido de información de terceros.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-09-10 CVE Reserved
  • 2008-01-26 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-16 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-399: Resource Management Errors
CAPEC
References (28)
URL Date SRC
URL Date SRC
http://www.securityfocus.com/bid/27455 2018-10-15
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Icu-project
Search vendor "Icu-project"
International Components For Unicode
Search vendor "Icu-project" for product "International Components For Unicode"
<= 3.8.1
Search vendor "Icu-project" for product "International Components For Unicode" and version " <= 3.8.1"
c\/c\+\+
Affected