The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.
References
Link | Resource |
---|---|
https://github.com/clintongormley/perl-html-stripscripts/issues/3 | Exploit Issue Tracking Third Party Advisory |
https://lists.debian.org/debian-lts-announce/2023/01/msg00036.html | Mailing List Third Party Advisory |
https://www.debian.org/security/2023/dsa-5339 |
Information
Published : 2023-01-20 17:15
Updated : 2023-02-05 16:15
NVD link : CVE-2023-24038
Mitre link : CVE-2023-24038
JSON object : View
CWE
Products Affected
debian
- debian_linux
html-stripscripts_project
- html-stripscripts