« Volver al listado

CVE-2008-0171

Estado: ModificadaMedia (5)—

regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-0171",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-01-17T23:00:00.000",
  "references": [
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=205955",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28511",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28527",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28545",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28705",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28860",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28943",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29323",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/48099",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://svn.boost.org/trac/boost/changeset/42674",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://svn.boost.org/trac/boost/changeset/42745",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/488102/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/27325",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ubuntu.com/usn/usn-570-1",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0249",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://issues.rpath.com/browse/RPL-2143",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=205955",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28511",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28527",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28545",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28705",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28860",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28943",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/29323",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/48099",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://svn.boost.org/trac/boost/changeset/42674",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://svn.boost.org/trac/boost/changeset/42745",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/488102/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/27325",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/usn-570-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0249",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.rpath.com/browse/RPL-2143",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression."
    },
    {
      "lang": "es",
      "value": "regex/v4/perl_matcher_non_recursive.hpp en la librería de expresiones regulares (también conocido como Boost.Regex) de Boost 1.33 y 1.34 permite a atacantes remotos dependientes de contexto provocar una denegación de servicio (fallo de aserción y caída) mediante una expresión regular inválida."
    }
  ],
  "lastModified": "2026-06-16T22:49:04.380",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:boost:boost:1.33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7A527FE-ED5E-4C9A-823C-0D76B1885691"
            },
            {
              "criteria": "cpe:2.3:a:boost:boost:1.34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9CAD8FD-3F47-4AA4-9B97-41892E58FB57"
            },
            {
              "criteria": "cpe:2.3:a:boost:boost_regex_library:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81538702-CFC1-4A99-96B9-F8745F8D1D53"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "This issue did not affect the version of boost as shipped with Red Hat Enterprise Linux 4.\n\nFor Red Hat Enterprise Linux 5, Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2008-0171\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.",
      "lastModified": "2008-05-12T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}