CVE-2007-6067

Exp

Algorithmic complexity vulnerability in the regular expression parser in TCL before 8.4.17, as used in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, and 7.4 before 7.4.19, allows remote authenticated users to cause a denial of service (memory consumption) via a crafted "complex" regular expression with doubly-nested states.

Published: 2008-01-09 Last update: 2026-04-23 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2007-6067 is rated High Exploit Risk (76.8/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 3.89%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +3.48% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2007-6067

EDB-ID Source Kind Published Link
nvd_ref exploit_tag Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2007-6067

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.41% 3.89% +3.48%
2 2026-06-07 0.53% 0.41% -0.12%
3 2026-04-12 0.53%

Full EPSS history (20 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2007-6067

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.8 2.0 MEDIUM
AV:N/AC:L/Au:S/C:N/I:N/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:S)
A single authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:C)
Complete availability impact.
8.0 6.9 [email protected]

Weakness enumeration for CVE-2007-6067

OS Trackers for CVE-2007-6067

vendor priority summary link
gentoo high CVE-2007-6067: 1 GLSA(s) (200801-15), 1 atom(s) (dev-db/postgresql); latest impact high. https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2007-6067
redhat low https://access.redhat.com/security/cve/CVE-2007-6067
ubuntu medium CVE-2007-6067 medium priority: Ubuntu including 2 source packages (postgresql-8.1, postgresql-8.2), 14 status rows across 7 suites (dapper, edgy, feisty, gutsy, hardy, intrepid, upstream): DNE 5, released 5, ignored 2, needs-triage 2. https://ubuntu.com/security/CVE-2007-6067

Affected software / configurations for CVE-2007-6067

Vendor Product Version Raw CPE
postgresql postgresql 7.3 cpe:2.3:a:postgresql:postgresql:7.3:*:*:*:*:*:*:*
postgresql postgresql 7.3.1 cpe:2.3:a:postgresql:postgresql:7.3.1:*:*:*:*:*:*:*
postgresql postgresql 7.3.2 cpe:2.3:a:postgresql:postgresql:7.3.2:*:*:*:*:*:*:*
postgresql postgresql 7.3.3 cpe:2.3:a:postgresql:postgresql:7.3.3:*:*:*:*:*:*:*
postgresql postgresql 7.3.4 cpe:2.3:a:postgresql:postgresql:7.3.4:*:*:*:*:*:*:*
postgresql postgresql 7.3.6 cpe:2.3:a:postgresql:postgresql:7.3.6:*:*:*:*:*:*:*
postgresql postgresql 7.3.8 cpe:2.3:a:postgresql:postgresql:7.3.8:*:*:*:*:*:*:*
postgresql postgresql 7.3.9 cpe:2.3:a:postgresql:postgresql:7.3.9:*:*:*:*:*:*:*
postgresql postgresql 7.3.10 cpe:2.3:a:postgresql:postgresql:7.3.10:*:*:*:*:*:*:*
postgresql postgresql 7.3.11 cpe:2.3:a:postgresql:postgresql:7.3.11:*:*:*:*:*:*:*
postgresql postgresql 7.3.12 cpe:2.3:a:postgresql:postgresql:7.3.12:*:*:*:*:*:*:*
postgresql postgresql 7.3.13 cpe:2.3:a:postgresql:postgresql:7.3.13:*:*:*:*:*:*:*
postgresql postgresql 7.3.14 cpe:2.3:a:postgresql:postgresql:7.3.14:*:*:*:*:*:*:*
postgresql postgresql 7.3.15 cpe:2.3:a:postgresql:postgresql:7.3.15:*:*:*:*:*:*:*
postgresql postgresql 7.3.16 cpe:2.3:a:postgresql:postgresql:7.3.16:*:*:*:*:*:*:*
postgresql postgresql 7.3.19 cpe:2.3:a:postgresql:postgresql:7.3.19:*:*:*:*:*:*:*
postgresql postgresql 7.4 cpe:2.3:a:postgresql:postgresql:7.4:*:*:*:*:*:*:*
postgresql postgresql 7.4.1 cpe:2.3:a:postgresql:postgresql:7.4.1:*:*:*:*:*:*:*
postgresql postgresql 7.4.2 cpe:2.3:a:postgresql:postgresql:7.4.2:*:*:*:*:*:*:*
postgresql postgresql 7.4.3 cpe:2.3:a:postgresql:postgresql:7.4.3:*:*:*:*:*:*:*
postgresql postgresql 7.4.4 cpe:2.3:a:postgresql:postgresql:7.4.4:*:*:*:*:*:*:*
postgresql postgresql 7.4.5 cpe:2.3:a:postgresql:postgresql:7.4.5:*:*:*:*:*:*:*
postgresql postgresql 7.4.6 cpe:2.3:a:postgresql:postgresql:7.4.6:*:*:*:*:*:*:*
postgresql postgresql 7.4.7 cpe:2.3:a:postgresql:postgresql:7.4.7:*:*:*:*:*:*:*
postgresql postgresql 7.4.8 cpe:2.3:a:postgresql:postgresql:7.4.8:*:*:*:*:*:*:*
postgresql postgresql 7.4.9 cpe:2.3:a:postgresql:postgresql:7.4.9:*:*:*:*:*:*:*
postgresql postgresql 7.4.10 cpe:2.3:a:postgresql:postgresql:7.4.10:*:*:*:*:*:*:*
postgresql postgresql 7.4.11 cpe:2.3:a:postgresql:postgresql:7.4.11:*:*:*:*:*:*:*
postgresql postgresql 7.4.12 cpe:2.3:a:postgresql:postgresql:7.4.12:*:*:*:*:*:*:*
postgresql postgresql 7.4.13 cpe:2.3:a:postgresql:postgresql:7.4.13:*:*:*:*:*:*:*
postgresql postgresql 7.4.14 cpe:2.3:a:postgresql:postgresql:7.4.14:*:*:*:*:*:*:*
postgresql postgresql 7.4.16 cpe:2.3:a:postgresql:postgresql:7.4.16:*:*:*:*:*:*:*
postgresql postgresql 7.4.17 cpe:2.3:a:postgresql:postgresql:7.4.17:*:*:*:*:*:*:*
postgresql postgresql 8.0 cpe:2.3:a:postgresql:postgresql:8.0:*:*:*:*:*:*:*
postgresql postgresql 8.0.1 cpe:2.3:a:postgresql:postgresql:8.0.1:*:*:*:*:*:*:*
postgresql postgresql 8.0.2 cpe:2.3:a:postgresql:postgresql:8.0.2:*:*:*:*:*:*:*
postgresql postgresql 8.0.3 cpe:2.3:a:postgresql:postgresql:8.0.3:*:*:*:*:*:*:*
postgresql postgresql 8.0.4 cpe:2.3:a:postgresql:postgresql:8.0.4:*:*:*:*:*:*:*
postgresql postgresql 8.0.5 cpe:2.3:a:postgresql:postgresql:8.0.5:*:*:*:*:*:*:*
postgresql postgresql 8.0.7 cpe:2.3:a:postgresql:postgresql:8.0.7:*:*:*:*:*:*:*
postgresql postgresql 8.0.8 cpe:2.3:a:postgresql:postgresql:8.0.8:*:*:*:*:*:*:*
postgresql postgresql 8.0.9 cpe:2.3:a:postgresql:postgresql:8.0.9:*:*:*:*:*:*:*
postgresql postgresql 8.0.11 cpe:2.3:a:postgresql:postgresql:8.0.11:*:*:*:*:*:*:*
postgresql postgresql 8.0.13 cpe:2.3:a:postgresql:postgresql:8.0.13:*:*:*:*:*:*:*
postgresql postgresql 8.0.317 cpe:2.3:a:postgresql:postgresql:8.0.317:*:*:*:*:*:*:*
postgresql postgresql 8.1.1 cpe:2.3:a:postgresql:postgresql:8.1.1:*:*:*:*:*:*:*
postgresql postgresql 8.1.3 cpe:2.3:a:postgresql:postgresql:8.1.3:*:*:*:*:*:*:*
postgresql postgresql 8.1.4 cpe:2.3:a:postgresql:postgresql:8.1.4:*:*:*:*:*:*:*
postgresql postgresql 8.1.5 cpe:2.3:a:postgresql:postgresql:8.1.5:*:*:*:*:*:*:*
postgresql postgresql 8.1.7 cpe:2.3:a:postgresql:postgresql:8.1.7:*:*:*:*:*:*:*
postgresql postgresql 8.1.8 cpe:2.3:a:postgresql:postgresql:8.1.8:*:*:*:*:*:*:*
postgresql postgresql 8.1.9 cpe:2.3:a:postgresql:postgresql:8.1.9:*:*:*:*:*:*:*
postgresql postgresql 8.2 cpe:2.3:a:postgresql:postgresql:8.2:*:*:*:*:*:*:*
postgresql postgresql 8.2.2 cpe:2.3:a:postgresql:postgresql:8.2.2:*:*:*:*:*:*:*
postgresql postgresql 8.2.3 cpe:2.3:a:postgresql:postgresql:8.2.3:*:*:*:*:*:*:*
postgresql postgresql 8.2.4 cpe:2.3:a:postgresql:postgresql:8.2.4:*:*:*:*:*:*:*
tcl_tk tcl_tk <= 8.4.16 cpe:2.3:a:tcl_tk:tcl_tk:*:*:*:*:*:*:*:*

References for CVE-2007-6067

URL Tags
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01420154
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705
http://lists.opensuse.org/opensuse-security-announce/2008-02/msg00000.html
http://rhn.redhat.com/errata/RHSA-2013-0122.html
http://secunia.com/advisories/28359 Vendor Advisory
http://secunia.com/advisories/28376
http://secunia.com/advisories/28437
http://secunia.com/advisories/28438
http://secunia.com/advisories/28454
http://secunia.com/advisories/28455
http://secunia.com/advisories/28464
http://secunia.com/advisories/28477
http://secunia.com/advisories/28479
http://secunia.com/advisories/28679
http://secunia.com/advisories/28698
http://secunia.com/advisories/29638
http://security.gentoo.org/glsa/glsa-200801-15.xml
http://securitytracker.com/id?1019157
http://sourceforge.net/project/shownotes.php?release_id=565440&group_id=10894
http://sourceforge.net/tracker/index.php?func=detail&aid=1810264&group_id=10894&atid=110894 Exploit
http://sunsolve.sun.com/search/document.do?assetkey=1-26-103197-1
http://sunsolve.sun.com/search/document.do?assetkey=1-66-200559-1
http://www.debian.org/security/2008/dsa-1460
http://www.debian.org/security/2008/dsa-1463
http://www.mandriva.com/security/advisories?name=MDVSA-2008:004
http://www.postgresql.org/about/news.905
http://www.redhat.com/support/errata/RHSA-2008-0038.html
http://www.redhat.com/support/errata/RHSA-2008-0040.html
http://www.securityfocus.com/archive/1/485864/100/0/threaded
http://www.securityfocus.com/archive/1/486407/100/0/threaded
http://www.securityfocus.com/bid/27163 Patch
http://www.vupen.com/english/advisories/2008/0061
http://www.vupen.com/english/advisories/2008/0109
http://www.vupen.com/english/advisories/2008/1071/references
https://exchange.xforce.ibmcloud.com/vulnerabilities/39498
https://issues.rpath.com/browse/RPL-1768
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10235
https://usn.ubuntu.com/568-1/
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00397.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00469.html
cvelogic Threat Intelligence