CVE-2009-3627
Published: 29 October 2009
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.
Priority
Status
Package | Release | Status |
---|---|---|
libhtml-parser-perl Launchpad, Ubuntu, Debian |
upstream |
Released
(3.63)
|
dapper |
Released
(3.48-1ubuntu0.1)
|
|
hardy |
Released
(3.56-1ubuntu0.1)
|
|
intrepid |
Released
(3.56-1ubuntu2.1)
|
|
jaunty |
Released
(3.59-1ubuntu1.1)
|
|
karmic |
Released
(3.61-1ubuntu0.1)
|
|
Patches: upstream: http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c |