Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2009-3627

Published: 29 October 2009

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

Priority

Medium

Status

Package Release Status
libhtml-parser-perl
Launchpad, Ubuntu, Debian
upstream
Released (3.63)
dapper
Released (3.48-1ubuntu0.1)
hardy
Released (3.56-1ubuntu0.1)
intrepid
Released (3.56-1ubuntu2.1)
jaunty
Released (3.59-1ubuntu1.1)
karmic
Released (3.61-1ubuntu0.1)
Patches:
upstream: http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c