ACCESS Unknown

Notified:  February 06, 2015 Updated: February 06, 2015

Status

Unknown

Vendor Statement

No statement is currently available from the vendor regarding this vulnerability.

Vendor References

    Alcatel-Lucent Unknown

    Notified:  February 06, 2015 Updated: February 06, 2015

    Status

    Unknown

    Vendor Statement

    No statement is currently available from the vendor regarding this vulnerability.

    Vendor References

      Apple Unknown

      Notified:  February 06, 2015 Updated: February 06, 2015

      Status

      Unknown

      Vendor Statement

      No statement is currently available from the vendor regarding this vulnerability.

      Vendor References

        Arch Linux Unknown

        Notified:  February 06, 2015 Updated: February 06, 2015

        Status

        Unknown

        Vendor Statement

        No statement is currently available from the vendor regarding this vulnerability.

        Vendor References

          AT&T Unknown

          Notified:  February 06, 2015 Updated: February 06, 2015

          Status

          Unknown

          Vendor Statement

          No statement is currently available from the vendor regarding this vulnerability.

          Vendor References

            Avaya, Inc. Unknown

            Notified:  February 06, 2015 Updated: February 06, 2015

            Status

            Unknown

            Vendor Statement

            No statement is currently available from the vendor regarding this vulnerability.

            Vendor References

              Barracuda Networks Unknown

              Notified:  February 06, 2015 Updated: February 06, 2015

              Status

              Unknown

              Vendor Statement

              No statement is currently available from the vendor regarding this vulnerability.

              Vendor References

                Belkin, Inc. Unknown

                Notified:  February 06, 2015 Updated: February 06, 2015

                Status

                Unknown

                Vendor Statement

                No statement is currently available from the vendor regarding this vulnerability.

                Vendor References

                  Blue Coat Systems Unknown

                  Notified:  February 06, 2015 Updated: February 06, 2015

                  Status

                  Unknown

                  Vendor Statement

                  No statement is currently available from the vendor regarding this vulnerability.

                  Vendor References

                    CA Technologies Unknown

                    Notified:  February 06, 2015 Updated: February 06, 2015

                    Status

                    Unknown

                    Vendor Statement

                    No statement is currently available from the vendor regarding this vulnerability.

                    Vendor References

                      CentOS Unknown

                      Notified:  February 06, 2015 Updated: February 06, 2015

                      Status

                      Unknown

                      Vendor Statement

                      No statement is currently available from the vendor regarding this vulnerability.

                      Vendor References

                        Check Point Software Technologies Not Affected

                        Notified:  February 06, 2015 Updated: February 24, 2015

                        Statement Date:   February 24, 2015

                        Status

                        Not Affected

                        Vendor Statement

                        "Since all regcomp() calls are done with hard coded regular expressions – Check Point does not find our code exploitable by an attacker."

                        Vendor Information

                        We are not aware of further vendor information regarding this vulnerability.

                        Cisco Systems, Inc. Unknown

                        Notified:  February 06, 2015 Updated: February 06, 2015

                        Status

                        Unknown

                        Vendor Statement

                        No statement is currently available from the vendor regarding this vulnerability.

                        Vendor References

                          Debian GNU/Linux Affected

                          Notified:  February 06, 2015 Updated: February 09, 2015

                          Statement Date:   February 07, 2015

                          Status

                          Affected

                          Vendor Statement

                          No statement is currently available from the vendor regarding this vulnerability.

                          Vendor Information

                          We are not aware of further vendor information regarding this vulnerability.

                          DesktopBSD Unknown

                          Notified:  February 06, 2015 Updated: February 06, 2015

                          Status

                          Unknown

                          Vendor Statement

                          No statement is currently available from the vendor regarding this vulnerability.

                          Vendor References

                            D-Link Systems, Inc. Unknown

                            Notified:  February 06, 2015 Updated: February 06, 2015

                            Status

                            Unknown

                            Vendor Statement

                            No statement is currently available from the vendor regarding this vulnerability.

                            Vendor References

                              DragonFly BSD Project Affected

                              Notified:  February 06, 2015 Updated: February 13, 2015

                              Statement Date:   February 07, 2015

                              Status

                              Affected

                              Vendor Statement

                              "DragonFly is 64-bit only now so the current release is not affected.  However, older versions of DragonFly (prior to us going 64-bit only) are vulnerable.  Despite the vulnerability I'm not sure I would classify this as a serious problem because it is highly unlikely that programs using the library would allow a 700MB+ pattern string in the first place.  Patterns of that size certainly can't be passed on the command line due to OS exec argument buffer limitations. That said, we will commit a length check to avoid any possible overflow."

                              Vendor Information

                              The vendor has patched the issue; the git log is available at the URL below:

                              Vendor References

                              Enterasys Networks Unknown

                              Notified:  February 06, 2015 Updated: February 06, 2015

                              Status

                              Unknown

                              Vendor Statement

                              No statement is currently available from the vendor regarding this vulnerability.

                              Vendor References

                                Ericsson Unknown

                                Notified:  February 06, 2015 Updated: February 06, 2015

                                Status

                                Unknown

                                Vendor Statement

                                No statement is currently available from the vendor regarding this vulnerability.

                                Vendor References

                                  eSoft, Inc. Unknown

                                  Notified:  February 06, 2015 Updated: February 06, 2015

                                  Status

                                  Unknown

                                  Vendor Statement

                                  No statement is currently available from the vendor regarding this vulnerability.

                                  Vendor References

                                    Extreme Networks Unknown

                                    Notified:  February 06, 2015 Updated: February 06, 2015

                                    Status

                                    Unknown

                                    Vendor Statement

                                    No statement is currently available from the vendor regarding this vulnerability.

                                    Vendor References

                                      F5 Networks, Inc. Unknown

                                      Notified:  February 06, 2015 Updated: February 06, 2015

                                      Status

                                      Unknown

                                      Vendor Statement

                                      No statement is currently available from the vendor regarding this vulnerability.

                                      Vendor References

                                        Fedora Project Unknown

                                        Notified:  February 06, 2015 Updated: February 06, 2015

                                        Status

                                        Unknown

                                        Vendor Statement

                                        No statement is currently available from the vendor regarding this vulnerability.

                                        Vendor References

                                          Force10 Networks, Inc. Unknown

                                          Notified:  February 06, 2015 Updated: February 06, 2015

                                          Status

                                          Unknown

                                          Vendor Statement

                                          No statement is currently available from the vendor regarding this vulnerability.

                                          Vendor References

                                            Fortinet, Inc. Not Affected

                                            Notified:  February 06, 2015 Updated: February 27, 2015

                                            Statement Date:   February 27, 2015

                                            Status

                                            Not Affected

                                            Vendor Statement

                                            "Fortinet products are not affected by the Henry Spencer regular expressions (regex) library heap overflow vulnerability."

                                            Vendor Information

                                            We are not aware of further vendor information regarding this vulnerability.

                                            Foundry Networks, Inc. Unknown

                                            Notified:  February 06, 2015 Updated: February 06, 2015

                                            Status

                                            Unknown

                                            Vendor Statement

                                            No statement is currently available from the vendor regarding this vulnerability.

                                            Vendor References

                                              FreeBSD Project Affected

                                              Notified:  February 06, 2015 Updated: February 09, 2015

                                              Statement Date:   February 06, 2015

                                              Status

                                              Affected

                                              Vendor Statement

                                              No statement is currently available from the vendor regarding this vulnerability.

                                              Vendor Information

                                              We are not aware of further vendor information regarding this vulnerability.

                                              Gentoo Linux Unknown

                                              Notified:  February 06, 2015 Updated: February 06, 2015

                                              Status

                                              Unknown

                                              Vendor Statement

                                              No statement is currently available from the vendor regarding this vulnerability.

                                              Vendor References

                                                Global Technology Associates, Inc. Not Affected

                                                Notified:  February 06, 2015 Updated: February 09, 2015

                                                Statement Date:   February 09, 2015

                                                Status

                                                Not Affected

                                                Vendor Statement

                                                "No GTA firewalls running any version of GB-OS are vulnerable to the H. Spencer Regex vulnerability VU#695940."

                                                Vendor Information

                                                We are not aware of further vendor information regarding this vulnerability.

                                                Google Unknown

                                                Notified:  February 06, 2015 Updated: February 06, 2015

                                                Status

                                                Unknown

                                                Vendor Statement

                                                No statement is currently available from the vendor regarding this vulnerability.

                                                Vendor References

                                                  Hewlett-Packard Company Unknown

                                                  Notified:  February 06, 2015 Updated: February 06, 2015

                                                  Status

                                                  Unknown

                                                  Vendor Statement

                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                  Vendor References

                                                    Hitachi Unknown

                                                    Notified:  February 06, 2015 Updated: February 06, 2015

                                                    Status

                                                    Unknown

                                                    Vendor Statement

                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                    Vendor References

                                                      Huawei Technologies Unknown

                                                      Notified:  February 06, 2015 Updated: February 06, 2015

                                                      Status

                                                      Unknown

                                                      Vendor Statement

                                                      No statement is currently available from the vendor regarding this vulnerability.

                                                      Vendor References

                                                        IBM Corporation Unknown

                                                        Notified:  February 06, 2015 Updated: February 06, 2015

                                                        Status

                                                        Unknown

                                                        Vendor Statement

                                                        No statement is currently available from the vendor regarding this vulnerability.

                                                        Vendor References

                                                          IBM eServer Unknown

                                                          Notified:  February 06, 2015 Updated: February 06, 2015

                                                          Status

                                                          Unknown

                                                          Vendor Statement

                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                          Vendor References

                                                            Infoblox Unknown

                                                            Notified:  February 06, 2015 Updated: February 06, 2015

                                                            Status

                                                            Unknown

                                                            Vendor Statement

                                                            No statement is currently available from the vendor regarding this vulnerability.

                                                            Vendor References

                                                              Intel Corporation Unknown

                                                              Notified:  February 06, 2015 Updated: February 06, 2015

                                                              Status

                                                              Unknown

                                                              Vendor Statement

                                                              No statement is currently available from the vendor regarding this vulnerability.

                                                              Vendor References

                                                                Intoto Unknown

                                                                Notified:  February 06, 2015 Updated: February 06, 2015

                                                                Status

                                                                Unknown

                                                                Vendor Statement

                                                                No statement is currently available from the vendor regarding this vulnerability.

                                                                Vendor References

                                                                  Juniper Networks, Inc. Not Affected

                                                                  Notified:  February 06, 2015 Updated: February 09, 2015

                                                                  Statement Date:   February 07, 2015

                                                                  Status

                                                                  Not Affected

                                                                  Vendor Statement

                                                                  "As per our analysis of Junos OS, all our regcomp invocations happen with regular expressions hard coded in the source. We do not see any exploitable attack vector where an attacker can input or influence a regular expression."

                                                                  Vendor Information

                                                                  We are not aware of further vendor information regarding this vulnerability.

                                                                  m0n0wall Unknown

                                                                  Notified:  February 06, 2015 Updated: February 06, 2015

                                                                  Status

                                                                  Unknown

                                                                  Vendor Statement

                                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                                  Vendor References

                                                                    Mandriva S. A. Unknown

                                                                    Notified:  February 06, 2015 Updated: February 06, 2015

                                                                    Status

                                                                    Unknown

                                                                    Vendor Statement

                                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                                    Vendor References

                                                                      McAfee Unknown

                                                                      Notified:  February 06, 2015 Updated: February 06, 2015

                                                                      Status

                                                                      Unknown

                                                                      Vendor Statement

                                                                      No statement is currently available from the vendor regarding this vulnerability.

                                                                      Vendor References

                                                                        Microsoft Corporation Unknown

                                                                        Notified:  February 06, 2015 Updated: February 06, 2015

                                                                        Status

                                                                        Unknown

                                                                        Vendor Statement

                                                                        No statement is currently available from the vendor regarding this vulnerability.

                                                                        Vendor References

                                                                          MySQL Unknown

                                                                          Notified:  February 06, 2015 Updated: February 09, 2015

                                                                          Status

                                                                          Unknown

                                                                          Vendor Statement

                                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                                          Vendor Information

                                                                          We are not aware of further vendor information regarding this vulnerability.

                                                                          NetBSD Affected

                                                                          Notified:  February 06, 2015 Updated: February 09, 2015

                                                                          Statement Date:   February 07, 2015

                                                                          Status

                                                                          Affected

                                                                          Vendor Statement

                                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                                          Vendor Information

                                                                          We are not aware of further vendor information regarding this vulnerability.

                                                                          netfilter Unknown

                                                                          Notified:  February 06, 2015 Updated: February 06, 2015

                                                                          Status

                                                                          Unknown

                                                                          Vendor Statement

                                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                                          Vendor References

                                                                            Nokia Unknown

                                                                            Notified:  February 06, 2015 Updated: February 06, 2015

                                                                            Status

                                                                            Unknown

                                                                            Vendor Statement

                                                                            No statement is currently available from the vendor regarding this vulnerability.

                                                                            Vendor References

                                                                              Novell, Inc. Unknown

                                                                              Notified:  February 06, 2015 Updated: February 06, 2015

                                                                              Status

                                                                              Unknown

                                                                              Vendor Statement

                                                                              No statement is currently available from the vendor regarding this vulnerability.

                                                                              Vendor References

                                                                                OmniTI Unknown

                                                                                Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                Status

                                                                                Unknown

                                                                                Vendor Statement

                                                                                No statement is currently available from the vendor regarding this vulnerability.

                                                                                Vendor References

                                                                                  OpenBSD Not Affected

                                                                                  Notified:  February 06, 2015 Updated: February 09, 2015

                                                                                  Statement Date:   February 06, 2015

                                                                                  Status

                                                                                  Not Affected

                                                                                  Vendor Statement

                                                                                  "Since May 2014, we use the following int overflow avoiding construct: regcomp.c: p->strip = reallocarray(NULL, p->ssize, sizeof(sop)); Combined with the previous line, we believe this cannot attain int overflow."

                                                                                  Vendor Information

                                                                                  We are not aware of further vendor information regarding this vulnerability.

                                                                                  openSUSE project Unknown

                                                                                  Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                  Status

                                                                                  Unknown

                                                                                  Vendor Statement

                                                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                                                  Vendor References

                                                                                    Openwall GNU/*/Linux Unknown

                                                                                    Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                    Status

                                                                                    Unknown

                                                                                    Vendor Statement

                                                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                                                    Vendor References

                                                                                      Palo Alto Networks Unknown

                                                                                      Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                      Status

                                                                                      Unknown

                                                                                      Vendor Statement

                                                                                      No statement is currently available from the vendor regarding this vulnerability.

                                                                                      Vendor References

                                                                                        PC-BSD Unknown

                                                                                        Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                        Status

                                                                                        Unknown

                                                                                        Vendor Statement

                                                                                        No statement is currently available from the vendor regarding this vulnerability.

                                                                                        Vendor References

                                                                                          Peplink Unknown

                                                                                          Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                          Status

                                                                                          Unknown

                                                                                          Vendor Statement

                                                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                                                          Vendor References

                                                                                            Process Software Unknown

                                                                                            Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                            Status

                                                                                            Unknown

                                                                                            Vendor Statement

                                                                                            No statement is currently available from the vendor regarding this vulnerability.

                                                                                            Vendor References

                                                                                              Q1 Labs Unknown

                                                                                              Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                              Status

                                                                                              Unknown

                                                                                              Vendor Statement

                                                                                              No statement is currently available from the vendor regarding this vulnerability.

                                                                                              Vendor References

                                                                                                QNX Software Systems Inc. Unknown

                                                                                                Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                Status

                                                                                                Unknown

                                                                                                Vendor Statement

                                                                                                No statement is currently available from the vendor regarding this vulnerability.

                                                                                                Vendor References

                                                                                                  Quagga Unknown

                                                                                                  Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                  Status

                                                                                                  Unknown

                                                                                                  Vendor Statement

                                                                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                                                                  Vendor References

                                                                                                    Red Hat, Inc. Unknown

                                                                                                    Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                    Status

                                                                                                    Unknown

                                                                                                    Vendor Statement

                                                                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                                                                    Vendor References

                                                                                                      SafeNet Unknown

                                                                                                      Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                      Status

                                                                                                      Unknown

                                                                                                      Vendor Statement

                                                                                                      No statement is currently available from the vendor regarding this vulnerability.

                                                                                                      Vendor References

                                                                                                        Slackware Linux Inc. Unknown

                                                                                                        Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                        Status

                                                                                                        Unknown

                                                                                                        Vendor Statement

                                                                                                        No statement is currently available from the vendor regarding this vulnerability.

                                                                                                        Vendor References

                                                                                                          SmoothWall Unknown

                                                                                                          Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                          Status

                                                                                                          Unknown

                                                                                                          Vendor Statement

                                                                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                                                                          Vendor References

                                                                                                            Snort Unknown

                                                                                                            Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                            Status

                                                                                                            Unknown

                                                                                                            Vendor Statement

                                                                                                            No statement is currently available from the vendor regarding this vulnerability.

                                                                                                            Vendor References

                                                                                                              Sourcefire Unknown

                                                                                                              Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                              Status

                                                                                                              Unknown

                                                                                                              Vendor Statement

                                                                                                              No statement is currently available from the vendor regarding this vulnerability.

                                                                                                              Vendor References

                                                                                                                Stonesoft Unknown

                                                                                                                Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                Status

                                                                                                                Unknown

                                                                                                                Vendor Statement

                                                                                                                No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                Vendor References

                                                                                                                  SUSE Linux Unknown

                                                                                                                  Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                  Status

                                                                                                                  Unknown

                                                                                                                  Vendor Statement

                                                                                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                  Vendor References

                                                                                                                    Symantec Unknown

                                                                                                                    Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                    Status

                                                                                                                    Unknown

                                                                                                                    Vendor Statement

                                                                                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                    Vendor References

                                                                                                                      The PHP Group Unknown

                                                                                                                      Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                      Status

                                                                                                                      Unknown

                                                                                                                      Vendor Statement

                                                                                                                      No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                      Vendor References

                                                                                                                        TippingPoint Technologies Inc. Unknown

                                                                                                                        Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                        Status

                                                                                                                        Unknown

                                                                                                                        Vendor Statement

                                                                                                                        No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                        Vendor References

                                                                                                                          Turbolinux Unknown

                                                                                                                          Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                          Status

                                                                                                                          Unknown

                                                                                                                          Vendor Statement

                                                                                                                          No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                          Vendor References

                                                                                                                            Ubuntu Unknown

                                                                                                                            Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                            Status

                                                                                                                            Unknown

                                                                                                                            Vendor Statement

                                                                                                                            No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                            Vendor References

                                                                                                                              VMware Unknown

                                                                                                                              Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                              Status

                                                                                                                              Unknown

                                                                                                                              Vendor Statement

                                                                                                                              No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                              Vendor References

                                                                                                                                Vyatta Unknown

                                                                                                                                Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                                Status

                                                                                                                                Unknown

                                                                                                                                Vendor Statement

                                                                                                                                No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                                Vendor References

                                                                                                                                  Watchguard Technologies, Inc. Unknown

                                                                                                                                  Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                                  Status

                                                                                                                                  Unknown

                                                                                                                                  Vendor Statement

                                                                                                                                  No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                                  Vendor References

                                                                                                                                    Wind River Systems, Inc. Affected

                                                                                                                                    Notified:  February 06, 2015 Updated: February 09, 2015

                                                                                                                                    Statement Date:   February 09, 2015

                                                                                                                                    Status

                                                                                                                                    Affected

                                                                                                                                    Vendor Statement

                                                                                                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                                    Vendor Information

                                                                                                                                    We are not aware of further vendor information regarding this vulnerability.

                                                                                                                                    ZyXEL Unknown

                                                                                                                                    Notified:  February 06, 2015 Updated: February 06, 2015

                                                                                                                                    Status

                                                                                                                                    Unknown

                                                                                                                                    Vendor Statement

                                                                                                                                    No statement is currently available from the vendor regarding this vulnerability.

                                                                                                                                    Vendor References

                                                                                                                                      View all 77 vendors View less vendors