CVE-2008-0172

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
17/01/2008
Last modified:
09/04/2025

Description

The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ubuntu:ubuntu_linux:6.06_lts:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:6.10:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:7.04:*:*:*:*:*:*:*
cpe:2.3:o:ubuntu:ubuntu_linux:7.10:*:*:*:*:*:*:*
cpe:2.3:a:boost:boost:1.33:*:*:*:*:*:*:*
cpe:2.3:a:boost:boost:1.34:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools