CVE-2008-0172
Title: Boost Denial of Service (DoS)
Denial of Service (DoS)
Proof Of Concept
No public PoC currently indexed for CVE-2008-0172.
CWE Category
CWE-20
Published Date
Jan 17, 2008
Modified Date
Apr 09, 2025
Exploit Status
Not Found
Score
5.0
CVSS v2.0
Exploit Probability (EPSS)
2.17%
Vulnerability Summary
CVE-2008-0172: The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression.
Impacted Vendors
Reference Links
http://bugs.gentoo.org/show_bug.cgi?id=205955
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html
http://secunia.com/advisories/28511
http://secunia.com/advisories/28527
http://secunia.com/advisories/28545
http://secunia.com/advisories/28705
http://secunia.com/advisories/28860
http://secunia.com/advisories/28943
http://secunia.com/advisories/29323
http://secunia.com/advisories/48099
http://svn.boost.org/trac/boost/changeset/42674
http://svn.boost.org/trac/boost/changeset/42745
http://wiki.rpath.com/Advisories:rPSA-2008-0063
http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml
http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032
http://www.securityfocus.com/archive/1/488102/100/0/threaded
http://www.securityfocus.com/bid/27325
http://www.ubuntu.com/usn/usn-570-1
http://www.vupen.com/english/advisories/2008/0249
https://issues.rpath.com/browse/RPL-2143
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html
http://bugs.gentoo.org/show_bug.cgi?id=205955
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00004.html
http://secunia.com/advisories/28511
http://secunia.com/advisories/28527
http://secunia.com/advisories/28545
http://secunia.com/advisories/28705
http://secunia.com/advisories/28860
http://secunia.com/advisories/28943
http://secunia.com/advisories/29323
http://secunia.com/advisories/48099
http://svn.boost.org/trac/boost/changeset/42674
http://svn.boost.org/trac/boost/changeset/42745
http://wiki.rpath.com/Advisories:rPSA-2008-0063
http://www.gentoo.org/security/en/glsa/glsa-200802-08.xml
http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:032
http://www.securityfocus.com/archive/1/488102/100/0/threaded
http://www.securityfocus.com/bid/27325
http://www.ubuntu.com/usn/usn-570-1
http://www.vupen.com/english/advisories/2008/0249
https://issues.rpath.com/browse/RPL-2143
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00760.html
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
5.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:N/C:N/I:N/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2008-0172 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected Stack
No specific products linked.