The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://www.vupen.com/english/advisories/2009/3022 | patch vendor advisory vdb entry |
http://www.openwall.com/lists/oss-security/2009/10/23/9 | patch mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/53941 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=530604 | |
http://www.securityfocus.com/bid/36807 | patch vdb entry |
http://secunia.com/advisories/37155 | third party advisory vendor advisory |
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225 | patch |
http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c |