CVE-2007-4770

N/A Unknown
Published: January 29, 2008 Modified: April 23, 2026
View on NVD

Description

libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2008-0090.html
Source: cve@mitre.org
Third Party Advisory
http://secunia.com/advisories/28575
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/28615
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/28669
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/28783
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/29194
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/29242
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/29291
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/29294
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/29333
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/29852
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/29910
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/29987
Source: cve@mitre.org
Permissions Required
http://secunia.com/advisories/30179
Source: cve@mitre.org
Permissions Required
http://security.gentoo.org/glsa/glsa-200803-20.xml
Source: cve@mitre.org
Third Party Advisory
http://security.gentoo.org/glsa/glsa-200805-16.xml
Source: cve@mitre.org
Third Party Advisory
http://securitytracker.com/id?1019269
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0043
Source: cve@mitre.org
Third Party Advisory
http://www.debian.org/security/2008/dsa-1511
Source: cve@mitre.org
Third Party Advisory
http://www.openoffice.org/security/cves/CVE-2007-4770.html
Source: cve@mitre.org
Third Party Advisory
http://www.openoffice.org/security/cves/CVE-2007-5745.html
Source: cve@mitre.org
Third Party Advisory
http://www.securityfocus.com/bid/27455
Source: cve@mitre.org
Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-591-1
Source: cve@mitre.org
Third Party Advisory
http://www.vupen.com/english/advisories/2008/0282
Source: cve@mitre.org
Third Party Advisory
http://www.vupen.com/english/advisories/2008/0807/references
Source: cve@mitre.org
Third Party Advisory
http://www.vupen.com/english/advisories/2008/1375/references
Source: cve@mitre.org
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=429023
Source: cve@mitre.org
Issue Tracking Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/39938
Source: cve@mitre.org
Third Party Advisory VDB Entry
https://issues.rpath.com/browse/RPL-2199
Source: cve@mitre.org
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2008-0090.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://secunia.com/advisories/28575
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/28615
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/28669
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/28783
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/29194
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/29242
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/29291
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/29294
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/29333
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/29852
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/29910
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/29987
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://secunia.com/advisories/30179
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
http://security.gentoo.org/glsa/glsa-200803-20.xml
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://security.gentoo.org/glsa/glsa-200805-16.xml
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://securitytracker.com/id?1019269
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://sourceforge.net/mailarchive/message.php?msg_name=d03a2ffb0801221538x68825e42xb4a4aaf0fcccecbd%40mail.gmail.com
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link Patch Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-231641-1
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-233922-1
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0043
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.debian.org/security/2008/dsa-1511
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:026
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
http://www.novell.com/linux/security/advisories/2008_23_openoffice.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.openoffice.org/security/cves/CVE-2007-4770.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.openoffice.org/security/cves/CVE-2007-5745.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.securityfocus.com/archive/1/487677/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/27455
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
http://www.ubuntu.com/usn/usn-591-1
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.vupen.com/english/advisories/2008/0282
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.vupen.com/english/advisories/2008/0807/references
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
http://www.vupen.com/english/advisories/2008/1375/references
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=429023
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/39938
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory VDB Entry
https://issues.rpath.com/browse/RPL-2199
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11172
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5507
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00896.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00921.html
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

80 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
2.8%
85th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

icu-project