Description
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1923-1 | New libhtml-parser-perl packages fix denial of service |
EUVD |
EUVD-2009-3608 | The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character. |
Ubuntu USN |
USN-855-1 | libhtml-parser-perl vulnerability |
References
History
Wed, 28 May 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-07T06:38:28.315Z
Reserved: 2009-10-09T00:00:00.000Z
Link: CVE-2009-3627
No data.
Status : Modified
Published: 2009-10-29T14:30:01.203
Modified: 2026-04-23T00:35:47.467
Link: CVE-2009-3627
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Ubuntu USN