Lucene search

K
cve[email protected]CVE-2009-3627
HistoryOct 29, 2009 - 2:30 p.m.

CVE-2009-3627

2009-10-2914:30:01
CWE-20
web.nvd.nist.gov
32
security
html-parser
denial of service
cve-2009-3627
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

60.9%

The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.

Affected configurations

NVD
Node
derrick_oswaldhtml-parserRange3.54
OR
derrick_oswaldhtml-parserMatch1.00
OR
derrick_oswaldhtml-parserMatch1.1
OR
derrick_oswaldhtml-parserMatch1.2
OR
derrick_oswaldhtml-parserMatch1.3
OR
derrick_oswaldhtml-parserMatch1.4
OR
derrick_oswaldhtml-parserMatch1.5
OR
derrick_oswaldhtml-parserMatch1.6
OR
derrick_oswaldhtml-parserMatch1.41
OR
derrick_oswaldhtml-parserMatch1.42

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.1 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

60.9%