[tcl] [CVE-2007-4772] flaw in the Tcl regular expression handling engine

Bug #199114 reported by disabled.user
252
Affects Status Importance Assigned to Milestone
tcl8.4 (Ubuntu)
Fix Released
Low
Unassigned
Dapper
Won't Fix
Undecided
Unassigned
Hardy
Won't Fix
Low
Unassigned

Bug Description

Binary package hint: tcl

References:
MDVSA-2008:059 (http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:059)

Quoting:
"A flaw in the Tcl regular expression handling engine was originally
discovered by Will Drewry in the PostgreSQL database server's Tcl
regular expression engine. This flaw can result in an infinite loop
when processing certain regular expressions."

CVE References

Kees Cook (kees)
Changed in tcltk-defaults:
status: New → Confirmed
Changed in tcl8.4 (Ubuntu):
importance: Undecided → Low
Changed in tcl8.4 (Ubuntu Dapper):
status: New → Won't Fix
Changed in tcl8.4 (Ubuntu):
status: Confirmed → Fix Released
Changed in tcl8.4 (Ubuntu Hardy):
status: New → Confirmed
Changed in tcl8.4 (Ubuntu Hardy):
importance: Undecided → Low
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. hardy has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against hardy is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in tcl8.4 (Ubuntu Hardy):
status: Confirmed → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.