« Back to list

CVE-2008-0171

Status: ModifiedMedium (5)—

regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2008-0171",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-01-17T23:00:00.000",
  "references": [
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=205955",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28511",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28527",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28545",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28705",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28860",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28943",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29323",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/48099",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://svn.boost.org/trac/boost/changeset/42674",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://svn.boost.org/trac/boost/changeset/42745",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/488102/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/27325",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ubuntu.com/usn/usn-570-1",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0249",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://issues.rpath.com/browse/RPL-2143",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=205955",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28511",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28527",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28545",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28705",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28860",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28943",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/29323",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/48099",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://svn.boost.org/trac/boost/changeset/42674",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://svn.boost.org/trac/boost/changeset/42745",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/488102/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/27325",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ubuntu.com/usn/usn-570-1",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0249",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://issues.rpath.com/browse/RPL-2143",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression."
    },
    {
      "lang": "es",
      "value": "regex/v4/perl_matcher_non_recursive.hpp en la librería de expresiones regulares (también conocido como Boost.Regex) de Boost 1.33 y 1.34 permite a atacantes remotos dependientes de contexto provocar una denegación de servicio (fallo de aserción y caída) mediante una expresión regular inválida."
    }
  ],
  "lastModified": "2026-06-16T22:49:04.380",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:boost:boost:1.33:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B7A527FE-ED5E-4C9A-823C-0D76B1885691"
            },
            {
              "criteria": "cpe:2.3:a:boost:boost:1.34:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9CAD8FD-3F47-4AA4-9B97-41892E58FB57"
            },
            {
              "criteria": "cpe:2.3:a:boost:boost_regex_library:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81538702-CFC1-4A99-96B9-F8745F8D1D53"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "This issue did not affect the version of boost as shipped with Red Hat Enterprise Linux 4.\n\nFor Red Hat Enterprise Linux 5, Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2008-0171\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.",
      "lastModified": "2008-05-12T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}