CVE-2009-3627
29.10.2009, 14:30
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.Enginsight
Vendor | Product | Version |
---|---|---|
derrick_oswald | html-parser | 𝑥 ≤ 3.54 |
derrick_oswald | html-parser | 1.00 |
derrick_oswald | html-parser | 1.1 |
derrick_oswald | html-parser | 1.2 |
derrick_oswald | html-parser | 1.3 |
derrick_oswald | html-parser | 1.4 |
derrick_oswald | html-parser | 1.5 |
derrick_oswald | html-parser | 1.6 |
derrick_oswald | html-parser | 1.41 |
derrick_oswald | html-parser | 1.42 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References