MEDIUM
perl-HTML-Parser: Production of invalid (wide) character(s) while parsing HTML entity(ies) with invalid UTF-8 character(s)
Published Oct 29, 2009
4.3
MEDIUMCVSS 2.0
EPSS 1.73%
Description
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.
Affected products
No data.
OR
- ≤ 3.54
- 1.00
- 1.1
- 1.2
- 1.3
- 1.4
- 1.5
- 1.6
- 1.41
- 1.42
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect Red Hat Enterprise Linux 3, 4, or 5. This flaw can only lead to a denial of service if perl-HTML-Parser is used in conjunction with perl 5.10.1. If perl-HTML-Parser is used with earlier versions of perl, this flaw does not lead to a denial of service.
Weaknesses (1)
References (11)
- http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c x_refsource_CONFIRM
- http://secunia.com/advisories/37155 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.openwall.com/lists/oss-security/2009/10/23/9 mailing-listx_refsource_MLISTPatch
- http://www.securityfocus.com/bid/36807 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2009/3022 vdb-entryx_refsource_VUPENPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2009-3627 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=530604 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/53941 vdb-entryx_refsource_XF
- https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225 x_refsource_CONFIRMPatch
- https://nvd.nist.gov/vuln/detail/CVE-2009-3627
- https://www.cve.org/CVERecord?id=CVE-2009-3627
| Link | Providers | Tags |
|---|---|---|
| http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c | x_refsource_CONFIRM | |
| http://secunia.com/advisories/37155 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.openwall.com/lists/oss-security/2009/10/23/9 | mailing-listx_refsource_MLISTPatch | |
| http://www.securityfocus.com/bid/36807 | vdb-entryx_refsource_BIDPatch | |
| http://www.vupen.com/english/advisories/2009/3022 | vdb-entryx_refsource_VUPENPatchVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2009-3627 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=530604 | x_refsource_CONFIRMIssue Tracking | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/53941 | vdb-entryx_refsource_XF | |
| https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225 | x_refsource_CONFIRMPatch | |
| https://nvd.nist.gov/vuln/detail/CVE-2009-3627 | ||
| https://www.cve.org/CVERecord?id=CVE-2009-3627 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 29, 2009
Updated Aug 7, 2024
Reserved Oct 9, 2009
Link CVE-2009-3627
CISA Vulnrichment
Updated n/a