CVE-2009-3627

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
derrick_oswaldhtml-parser
𝑥
≤ 3.54
derrick_oswaldhtml-parser
1.00
derrick_oswaldhtml-parser
1.1
derrick_oswaldhtml-parser
1.2
derrick_oswaldhtml-parser
1.3
derrick_oswaldhtml-parser
1.4
derrick_oswaldhtml-parser
1.5
derrick_oswaldhtml-parser
1.6
derrick_oswaldhtml-parser
1.41
derrick_oswaldhtml-parser
1.42
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libhtml-parser-perl
bullseye
3.75-1
fixed
bookworm
3.81-1
fixed
sid
3.83-1
fixed
trixie
3.83-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libhtml-parser-perl
karmic
Fixed 3.61-1ubuntu0.1
released
jaunty
Fixed 3.59-1ubuntu1.1
released
intrepid
Fixed 3.56-1ubuntu2.1
released
hardy
Fixed 3.56-1ubuntu0.1
released
dapper
Fixed 3.48-1ubuntu0.1
released