CVE-2009-3626
published 2009-10-29CVE-2009-3626: Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is…
PriorityP415medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.20%
80.7th percentile
Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | perl | < perl 5.10.1-6 (bookworm) | perl 5.10.1-6 (bookworm) |
| perl | perl | — | — |
| perl | perl | >= 0 < 5.10.1-6 | 5.10.1-6 |
| perl | perl | >= 0 < 5.10.1-6 | 5.10.1-6 |
| perl | perl | >= 0 < 5.10.1-6 | 5.10.1-6 |
| perl | perl | >= 0 < 5.10.1-6 | 5.10.1-6 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2009-3626: perl - Perl 5.10.1 allows context-dependent attackers to cause a denial of service (app...
vendor_debian·2009·CVSS 5.0
CVE-2009-3626 [MEDIUM] CVE-2009-3626: perl - Perl 5.10.1 allows context-dependent attackers to cause a denial of service (app...
Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.
Scope: local
bookworm: resolved (fixed in 5.10.1-6)
bullseye: resolved (fixed in 5.10.1-6)
forky: resolved (fixed in 5.10.1-6)
sid: resolved (fixed in 5.10.1-6)
trixie: resolved (fixed in 5.10.1-6)
Red Hat
perl: regexp matcher crash on invalid UTF-8 characters
vendor_redhat·CVSS 5.0
CVE-2009-3626 [MEDIUM] perl: regexp matcher crash on invalid UTF-8 characters
perl: regexp matcher crash on invalid UTF-8 characters
Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.
Statement: Not vulnerable. This issue did not affect the versions of perl as shipped with Red Hat Enterprise Linux 3, 4, or 5.
GHSA
GHSA-pr3m-646v-qvfc: Perl 5
ghsa_unreviewed·2022-05-02
CVE-2009-3626 [MEDIUM] GHSA-pr3m-646v-qvfc: Perl 5
Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.
OSV
CVE-2009-3626: Perl 5
osv·2009-10-29·CVSS 5.0
CVE-2009-3626 [MEDIUM] CVE-2009-3626: Perl 5
Perl 5.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a UTF-8 character with a large, invalid codepoint, which is not properly handled during a regular-expression match.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2009-3626 perl: regexp matcher crash on invalid UTF-8 characters
bugzilla·2009-12-15·CVSS 5.0
CVE-2009-3626 [MEDIUM] CVE-2009-3626 perl: regexp matcher crash on invalid UTF-8 characters
CVE-2009-3626 perl: regexp matcher crash on invalid UTF-8 characters
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-3626 to the following vulnerability:
Perl 5.10.1 allows context-dependent attackers to cause a denial of service
(application crash) via a UTF-8 character with a large, invalid codepoint,
which is not properly handled during a regular-expression match.
References:
http://rt.perl.org/rt3/Public/Bug/Display.html?id=69973
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225
http://www.openwall.com/lists/oss-security/2009/10/23/8
http://perl5.git.perl.org/perl.git/commit/0abd0d78a73da1c4d13b1c700526b7e5d03b32d4
Bugzilla
CVE-2009-3627 perl-HTML-Parser: Production of invalid (wide) character(s) while parsing HTML entity(ies) with invalid UTF-8 character(s)
bugzilla·2009-10-23·CVSS 5.0
CVE-2009-3627 [MEDIUM] CVE-2009-3627 perl-HTML-Parser: Production of invalid (wide) character(s) while parsing HTML entity(ies) with invalid UTF-8 character(s)
CVE-2009-3627 perl-HTML-Parser: Production of invalid (wide) character(s) while parsing HTML entity(ies) with invalid UTF-8 character(s)
Originally Mark Martinec reported the following issue to be present in
HTML-Parser: [1]
http://github.com/gisle/html-parser/commit/b9aae1e43eb2c8e989510187cff0ba3e996f9a4c
After preliminary analysis we concluded this results in:
A denial of service flaw was found in the way HTML-Parser
used to decode certain HTML entities. A remote attacker
could provide a specially-crafted string (containing HTML
entities) leading to infinite loop, when processed by
the parser.
But further, more detailed analysis of the issue confirmed
there is no additional, separated security issue (to CVE-2009-3626)
present in HTML-Parser. While [1] is still bug, it only
"helps" to
http://perl5.git.perl.org/perl.git/commit/0abd0d78a73da1c4d13b1c700526b7e5d03b32d4http://rt.perl.org/rt3/Public/Bug/Display.html?id=69973http://rt.perl.org/rt3/Ticket/Attachment/617489/295383/http://secunia.com/advisories/37144http://securitytracker.com/id?1023077http://www.openwall.com/lists/oss-security/2009/10/23/8http://www.osvdb.org/59283http://www.securityfocus.com/bid/36812http://www.vupen.com/english/advisories/2009/3023https://exchange.xforce.ibmcloud.com/vulnerabilities/53939https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225http://perl5.git.perl.org/perl.git/commit/0abd0d78a73da1c4d13b1c700526b7e5d03b32d4http://rt.perl.org/rt3/Public/Bug/Display.html?id=69973http://rt.perl.org/rt3/Ticket/Attachment/617489/295383/http://secunia.com/advisories/37144http://securitytracker.com/id?1023077http://www.openwall.com/lists/oss-security/2009/10/23/8http://www.osvdb.org/59283http://www.securityfocus.com/bid/36812http://www.vupen.com/english/advisories/2009/3023https://exchange.xforce.ibmcloud.com/vulnerabilities/53939https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6225
2009-10-29
Published