← Vulnerability feed

Vulnerability record · CVE-2007-4771 · published 29 January 2008

CVE-2007-4771: Icu-project international components for unicode vulnerability

Icu Project · International Components For Unicode

Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack. NOTE: some of these details are obtained from third party information.

9.3 CVSS 2.0 High EPSS 2.5% · top 15.7% CWE-399 · CWE-399
9.3CVSS 2.0 base score
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
80References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack. NOTE: some of these details are obtained from third party information.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2008-0090.html Third Party Advisory
http://secunia.com/advisories/28575 Permissions Required
http://secunia.com/advisories/28615 Permissions Required
http://secunia.com/advisories/28669 Permissions Required
http://secunia.com/advisories/28783 Permissions Required
http://secunia.com/advisories/29194 Permissions Required
http://secunia.com/advisories/29242 Permissions Required
http://secunia.com/advisories/29291 Permissions Required
http://secunia.com/advisories/29294 Permissions Required
http://secunia.com/advisories/29333 Permissions Required
http://secunia.com/advisories/29852 Permissions Required
http://secunia.com/advisories/29910 Permissions Required
http://secunia.com/advisories/29987 Permissions Required
http://secunia.com/advisories/30179 Permissions Required
http://security.gentoo.org/glsa/glsa-200803-20.xml Third Party Advisory
http://security.gentoo.org/glsa/glsa-200805-16.xml Third Party Advisory
http://securitytracker.com/id?1019269 Third Party AdvisoryVDB Entry
http://sourceforge.net/mailarchive/message.php?msg_name=d03a2ffb0801221538x68825e42xb4a4aaf0fcccecbd%40mail.gmail.com Third Party Advisory
http://sunsolve.sun.com/search/document.do?assetkey=1-26-231641-1 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-233922-1 Broken Link
http://wiki.rpath.com/wiki/Advisories:rPSA-2008-0043 Third Party Advisory
http://www.debian.org/security/2008/dsa-1511 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDVSA-2008:026 Broken Link
http://www.novell.com/linux/security/advisories/2008_23_openoffice.html Third Party Advisory
http://www.openoffice.org/security/cves/CVE-2007-4770.html Third Party Advisory
http://www.openoffice.org/security/cves/CVE-2007-5745.html Third Party Advisory
http://www.securityfocus.com/archive/1/487677/100/0/threaded
http://www.securityfocus.com/bid/27455 PatchThird Party AdvisoryVDB Entry
http://www.ubuntu.com/usn/usn-591-1 Third Party Advisory
http://www.vupen.com/english/advisories/2008/0282 Third Party Advisory
http://www.vupen.com/english/advisories/2008/0807/references Third Party Advisory
http://www.vupen.com/english/advisories/2008/1375/references Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=429025 Issue TrackingThird Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/39936 Third Party AdvisoryVDB Entry
https://issues.rpath.com/browse/RPL-2199 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10507 Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5431 Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00896.html Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00921.html Third Party Advisory

Track CVE-2007-4771 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2015-5922Apple mac os x vulnerabilityUnspecified vulnerability in International Components for Unicode (ICU) before 53.1.0, as used in Apple OS X before 10.11 and watchOS before 2, has u…EPSS 3.0%9.8CVE-2018-18928Icu-project international components for unicode integer overflow vulnerabilityInternational Components for Unicode (ICU) for C/C++ 63.1 has an integer overflow in number::impl::DecimalQuantity::toScientificString() in i18n/numb…EPSS 2.9%9.8CVE-2017-17484Icu-project international components for unicode memory buffer overflow vulnerabilityThe ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ through 60.1 mishandles ucnv_convertEx calls fo…EPSS 4.6%9.8CVE-2017-14952Icu-project international components for unicode double free vulnerabilityDouble free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ through 59.1 allows remote attackers to execute arbitrary co…EPSS 5.1%9.8CVE-2014-9654Google chrome memory buffer overflow vulnerabilityThe Regular Expressions package in International Components for Unicode (ICU) for C/C++ before 2014-12-03, as used in Google Chrome before 40.0.2214.…EPSS 2.4%9.8CVE-2014-9911Icu-project international components for unicode memory buffer overflow vulnerabilityStack-based buffer overflow in the ures_getByKeyWithFallback function in common/uresbund.cpp in International Components for Unicode (ICU) before 54.…EPSS 5.5%9.8CVE-2016-7415Icu-project international components for unicode memory buffer overflow vulnerabilityStack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remot…EPSS 5.8%9.8CVE-2016-6293Icu-project international components for unicode memory buffer overflow vulnerabilityThe uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that…EPSS 5.0%

Source: NIST National Vulnerability Database (record CVE-2007-4771), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.