Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3627

Опубликовано: 22 окт. 2009
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

Отчет

This issue does not affect Red Hat Enterprise Linux 3, 4, or 5. This flaw can only lead to a denial of service if perl-HTML-Parser is used in conjunction with perl 5.10.1. If perl-HTML-Parser is used with earlier versions of perl, this flaw does not lead to a denial of service.

Дополнительная информация

https://bugzilla.redhat.com/show_bug.cgi?id=530604perl-HTML-Parser: Production of invalid (wide) character(s) while parsing HTML entity(ies) with invalid UTF-8 character(s)

EPSS

Процентиль: 72%
0.00726
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 16 лет назад

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

nvd
около 16 лет назад

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

debian
около 16 лет назад

The decode_entities function in util.c in HTML-Parser before 3.63 allo ...

github
больше 3 лет назад

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

EPSS

Процентиль: 72%
0.00726
Низкий

4.3 Medium

CVSS2