Upstream information
Description
The decode_entities function in util.c in HTML-Parser before 3.63 allows context-dependent attackers to cause a denial of service (infinite loop) via an incomplete SGML numeric character reference, which triggers generation of an invalid UTF-8 character.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)
Novell/SUSE information
Novell Bugzilla entry: 550076, 585716 SUSE Security Advisories:- SUSE-SR:2009:020, published Tue, 12 Jan 2010 10:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise 11 GA DEBUGINFO |
| sled11.x86-64 sle11-debuginfo.s390x sle11-debuginfo.x86 sle11-debuginfo.ppc sles11.s390x sled11.x86 sles11.x86 sle11-debuginfo.x86-64 sles11.ppc sles11.ia64 sles11.x86-64 sle11-debuginfo.ia64 SAT Patch Nr: 1495 |
| SUSE Linux Enterprise Desktop 11 GA SUSE Linux Enterprise Server 11 GA |
| sled11.x86-64 sle11-debuginfo.s390x sle11-debuginfo.x86 sle11-debuginfo.ppc sles11.s390x sled11.x86 sles11.x86 sle11-debuginfo.x86-64 sles11.ppc sles11.ia64 sles11.x86-64 sle11-debuginfo.ia64 SAT Patch Nr: 1495 |
| openSUSE 11.0 |
| |
| openSUSE 11.0 |
| |
| openSUSE 11.1 |
| |
| openSUSE 11.1 |
| |
| SUSE Linux Enterprise Desktop 10 SP3 for AMD64 and Intel EM64T SUSE Linux Enterprise Desktop 10 SP3 for x86 SUSE Linux Enterprise SDK 10 SP3 SUSE Linux Enterprise Server 10 SP3 |
| sles10-sp3.x86 sles10-sp3.x86-64 sles10-sp3.s390x sled10-sp3.x86 sled10-sp3.x86-64 sles10-sp3.ppc sles10-sp3.ia64 ZYPP Patch Nr: 6622 |
