4.3
CVSSv2

CVE-2009-3627

Published: 29/10/2009 Updated: 17/08/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The decode_entities function in util.c in HTML-Parser prior to 3.63 allows context-dependent malicious users to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

Vulnerable Product Search on Vulmon Subscribe to Product

derrick oswald html-parser 1.2

derrick oswald html-parser 1.3

derrick oswald html-parser 1.00

derrick oswald html-parser 1.1

derrick oswald html-parser 1.6

derrick oswald html-parser

derrick oswald html-parser 1.42

derrick oswald html-parser 1.5

derrick oswald html-parser 1.4

derrick oswald html-parser 1.41

Vendor Advisories

Debian Bug report logs - #552531 libhtml-parser-perl: decode_entities confused by trailing incomplete entity can lead to DoS attacks Package: libhtml-parser-perl; Maintainer for libhtml-parser-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libhtml-parser-perl is src:libhtml-parser-perl (PTS, bui ...
Mark Martinec discovered that HTML::Parser incorrectly handled strings with incomplete entities An attacker could send specially crafted input to applications that use HTML::Parser and cause a denial of service ...
A denial of service vulnerability has been found in libhtml-parser-perl, a collection of modules to parse HTML in text documents which is used by several other projects like eg SpamAssassin Mark Martinec discovered that the decode_entities() function will get stuck in an infinite loop when parsing certain HTML entities with invalid UTF-8 charact ...