The get_repeat_type function in basic_regex_creator.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (NULL dereference and crash) via an invalid regular expression.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-libs/boost. | Oct 30, 2017 | Jan 17, 2008 |
| Oracle_linux | — | Upgrade boost-develUpgrade boostUpgrade boost-doc | Oct 16, 2024 | Jan 17, 2008 |
| Suse | — | Upgrade boost-docUpgrade boost-devel-64bitUpgrade boostUpgrade boost-64bitUpgrade boost-develUpgrade suse-release | Feb 17, 2015 | Jan 17, 2008 |
| Ubuntu | — | Upgrade libboost-regex1.34.1Upgrade libboost-regex1.33.1 | Nov 8, 2024 | Jan 17, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub