CVE-2008-0171
Status: ModifiedMedium (5)—
regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.69%
- Percentile among all scored CVEs: 85
- Score date: 10/4/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (2)
CWEs
- CWE-20
References
- http://bugs.gentoo.org/show_bug.cgi?id=205955
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html
- http://secunia.com/advisories/28511
- http://secunia.com/advisories/28527
- http://secunia.com/advisories/28545
- http://secunia.com/advisories/28705
- http://secunia.com/advisories/28860
- http://secunia.com/advisories/28943
- http://secunia.com/advisories/29323
- http://secunia.com/advisories/48099
- http://svn.boost.org/trac/boost/changeset/42674
- http://svn.boost.org/trac/boost/changeset/42745
- http://wiki.rpath.com/Advisories:rPSA-2008-0063
- http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml
- http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032
- http://www.securityfocus.com/archive/1/488102/100/0/threaded
- http://www.securityfocus.com/bid/27325
- http://www.ubuntu.com/usn/usn-570-1
- http://www.vupen.com/english/advisories/2008/0249
- https://issues.rpath.com/browse/RPL-2143
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html
- http://bugs.gentoo.org/show_bug.cgi?id=205955
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html
- http://secunia.com/advisories/28511
- http://secunia.com/advisories/28527
- http://secunia.com/advisories/28545
- http://secunia.com/advisories/28705
- http://secunia.com/advisories/28860
- http://secunia.com/advisories/28943
- http://secunia.com/advisories/29323
- http://secunia.com/advisories/48099
- http://svn.boost.org/trac/boost/changeset/42674
- http://svn.boost.org/trac/boost/changeset/42745
- http://wiki.rpath.com/Advisories:rPSA-2008-0063
- http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml
- http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032
- http://www.securityfocus.com/archive/1/488102/100/0/threaded
- http://www.securityfocus.com/bid/27325
- http://www.ubuntu.com/usn/usn-570-1
- http://www.vupen.com/english/advisories/2008/0249
- https://issues.rpath.com/browse/RPL-2143
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html
Raw JSON (NVD)
Show
{
"id": "CVE-2008-0171",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-01-17T23:00:00.000",
"references": [
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=205955",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28511",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28527",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28545",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28705",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28860",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/28943",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/29323",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/48099",
"source": "cve@mitre.org"
},
{
"url": "http://svn.boost.org/trac/boost/changeset/42674",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://svn.boost.org/trac/boost/changeset/42745",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
"source": "cve@mitre.org"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/488102/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/27325",
"source": "cve@mitre.org"
},
{
"url": "http://www.ubuntu.com/usn/usn-570-1",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0249",
"source": "cve@mitre.org"
},
{
"url": "https://issues.rpath.com/browse/RPL-2143",
"source": "cve@mitre.org"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.gentoo.org/show_bug.cgi?id=205955",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28511",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28527",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28545",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28705",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28860",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/28943",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/29323",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/48099",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://svn.boost.org/trac/boost/changeset/42674",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://svn.boost.org/trac/boost/changeset/42745",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://wiki.rpath.com/Advisories:rPSA-2008-0063",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/488102/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/27325",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ubuntu.com/usn/usn-570-1",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/0249",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://issues.rpath.com/browse/RPL-2143",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression."
},
{
"lang": "es",
"value": "regex/v4/perl_matcher_non_recursive.hpp en la librería de expresiones regulares (también conocido como Boost.Regex) de Boost 1.33 y 1.34 permite a atacantes remotos dependientes de contexto provocar una denegación de servicio (fallo de aserción y caída) mediante una expresión regular inválida."
}
],
"lastModified": "2026-06-16T22:49:04.380",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:boost:boost:1.33:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B7A527FE-ED5E-4C9A-823C-0D76B1885691"
},
{
"criteria": "cpe:2.3:a:boost:boost:1.34:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C9CAD8FD-3F47-4AA4-9B97-41892E58FB57"
},
{
"criteria": "cpe:2.3:a:boost:boost_regex_library:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "81538702-CFC1-4A99-96B9-F8745F8D1D53"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "This issue did not affect the version of boost as shipped with Red Hat Enterprise Linux 4.\n\nFor Red Hat Enterprise Linux 5, Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2008-0171\n\nThe Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.",
"lastModified": "2008-05-12T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}