Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.66147
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1923-1)
Summary:The remote host is missing an update for the Debian 'libhtml-parser-perl' package(s) announced via the DSA-1923-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'libhtml-parser-perl' package(s) announced via the DSA-1923-1 advisory.

Vulnerability Insight:
A denial of service vulnerability has been found in libhtml-parser-perl, a collection of modules to parse HTML in text documents which is used by several other projects like e.g. SpamAssassin.

Mark Martinec discovered that the decode_entities() function will get stuck in an infinite loop when parsing certain HTML entities with invalid UTF-8 characters. An attacker can use this to perform denial of service attacks by submitting crafted HTML to an application using this functionality.

For the oldstable distribution (etch), this problem has been fixed in version 3.55-1+etch1.

For the stable distribution (lenny), this problem has been fixed in version 3.56-1+lenny1.

For the testing (squeeze) and unstable (sid) distribution, this problem will be fixed soon.

We recommend that you upgrade your libhtml-parser-perl packages.

Affected Software/OS:
'libhtml-parser-perl' package(s) on Debian 4, Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2009-3627
36807
http://www.securityfocus.com/bid/36807
37155
http://secunia.com/advisories/37155
ADV-2009-3022
http://www.vupen.com/english/advisories/2009/3022
[oss-security] 20091023 CVE-2009-3627 assignment notification - HTML-Parser-3.63
http://www.openwall.com/lists/oss-security/2009/10/23/9
htmlparser-decodeentities-dos(53941)
https://exchange.xforce.ibmcloud.com/vulnerabilities/53941
http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c
https://bugzilla.redhat.com/show_bug.cgi?id=530604
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.