CVE-2009-3627
Summary
| CVE | CVE-2009-3627 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-10-29 14:30:01 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Derrick Oswald | Html-parser | 1.00 | All | All | All |
| Application | Derrick Oswald | Html-parser | 1.1 | All | All | All |
| Application | Derrick Oswald | Html-parser | 1.2 | All | All | All |
| Application | Derrick Oswald | Html-parser | 1.3 | All | All | All |
| Application | Derrick Oswald | Html-parser | 1.4 | All | All | All |
| Application | Derrick Oswald | Html-parser | 1.41 | All | All | All |
| Application | Derrick Oswald | Html-parser | 1.42 | All | All | All |
| Application | Derrick Oswald | Html-parser | 1.5 | All | All | All |
| Application | Derrick Oswald | Html-parser | 1.6 | All | All | All |
| Application | Derrick Oswald | Html-parser | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 530604 – (CVE-2009-3627) CVE-2009-3627 perl-HTML-Parser: Production of invalid (wide) character(s) while parsing HTML entity(ies) with invalid UTF-8 character(s) | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| HTML-Parser Invalid HTML Entity Remote Denial of Service Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| HTML-Parser "decode_entities()" Denial of Service - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Bug 6225 – Invalid numerical HTML entity crashes perl | af854a3a-2127-422b-91ae-364da2661108 | issues.apache.org | Patch |
| decode_entities confused by trailing incomplete entity · gisle/html-parser@b9aae1e · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| oss-security - CVE-2009-3627 assignment notification - HTML-Parser-3.63 | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-11-19 | Mark J Cox | This issue does not affect Red Hat Enterprise Linux 3, 4, or 5. This flaw can only lead to a denial of service if perl-HTML-Parser is used in conjunction with perl 5.10.1. If perl-HTML-Parser is used with earlier versions of perl, this flaw does not lead to a denial of service. |
There are currently no legacy QID mappings associated with this CVE.