FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-3627

This CVE name corresponds to:

Entered Topic
2009-11-06 p5-HTML-Parser -- denial of service

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-3627
Phase Assigned(20091009)

Description

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

References

Source Reference
MLIST [oss-security] 20091023 CVE-2009-3627 assignment notification - HTML-Parser-3.63
CONFIRM http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c
CONFIRM https://bugzilla.redhat.com/show_bug.cgi?id=530604
CONFIRM https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225
BID 36807
SECUNIA 37155
VUPEN ADV-2009-3022
XF htmlparser-decodeentities-dos(53941)