Summary
The remote host is missing an update to libhtml-parser-perl announced via advisory USN-855-1.
Solution
The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 6.06 LTS:
libhtml-parser-perl 3.48-1ubuntu0.1
Ubuntu 8.04 LTS:
libhtml-parser-perl 3.56-1ubuntu0.1
Ubuntu 8.10:
libhtml-parser-perl 3.56-1ubuntu2.1
Ubuntu 9.04:
libhtml-parser-perl 3.59-1ubuntu1.1
Ubuntu 9.10:
libhtml-parser-perl 3.61-1ubuntu0.1
In general, a standard system upgrade is sufficient to effect the necessary changes.
https://secure1.securityspace.com/smysecure/catid.html?in=USN-855-1
Insight
Mark Martinec discovered that HTML::Parser incorrectly handled strings with incomplete entities. An attacker could send specially crafted input to applications that use HTML::Parser and cause a denial of service.
Severity
Classification
-
CVE CVE-2009-3627 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:N/A:P
Related Vulnerabilities