VDB
CVE-2008-0171
CVE-2008-0171
PUBLISHED
CVSS 5 MEDIUM
regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.
EPSS 2.69% · 85.3th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
2.69%
85.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| boost | boost_regex_library | |
| boost | boost | 1.34, 1.33 |
| n/a | n/a | n/a |
Timeline
- Jan 17, 2008 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Oct 28, 2022 EPSS Score
- Dec 20, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 10, 2023 EPSS Score
References
- 28511 third-party-advisory
- 28545 third-party-advisory
- SUSE-SR:2008:006 vendor-advisory
- http://bugs.gentoo.org/show_bug.cgi?id=205955 url
- http://wiki.rpath.com/Advisories:rPSA-2008-0063 url
- 48099 third-party-advisory
- ADV-2008-0249 vdb
- 27325 vdb
- 28860 third-party-advisory
- http://svn.boost.org/trac/boost/changeset/42745 url
- 28943 third-party-advisory
- http://svn.boost.org/trac/boost/changeset/42674 url
- https://issues.rpath.com/browse/RPL-2143 url
- FEDORA-2008-0880 vendor-advisory
- 20080213 rPSA-2008-0063-1 boost mailing-list
- 28705 third-party-advisory
- GLSA-200802-08 vendor-advisory
- 28527 third-party-advisory
- USN-570-1 vendor-advisory
- 29323 third-party-advisory
…and 2 more