CVE-2007-4771Improper Restriction of Operations within the Bounds of a Memory Buffer in International Components FOR Unicode

CWE-3998 documents8 sources
Severity
9.3CRITICALNVD
EPSS
2.3%
top 15.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 29
Latest updateMay 1

Description

Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-78gp-g683-v26p: Heap-based buffer overflow in the doInterval function in regexcmp2022-05-01
OSV
CVE-2007-4771: Heap-based buffer overflow in the doInterval function in regexcmp2008-01-29
CVEList
CVE-2007-4771: Heap-based buffer overflow in the doInterval function in regexcmp2008-01-28

📋Vendor Advisories

3
Ubuntu
libicu vulnerabilities2008-03-24
Red Hat
libicu incomplete interval handling2008-01-22
Debian
CVE-2007-4771: icu - Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu ...2007

💬Community

1
Bugzilla
CVE-2007-4771 libicu incomplete interval handling2008-01-16
CVE-2007-4771 — CRITICAL severity | cvebase