id: PYSEC-2012-14 details: Universal Feed Parser (aka feedparser or python-feedparser) before 5.1.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML ENTITY declaration in a non-ASCII encoded document. affected: - package: name: feedparser ecosystem: PyPI purl: pkg:pypi/feedparser ranges: - type: ECOSYSTEM events: - introduced: '0' - fixed: 5.1.2 versions: - '4.1' - '5.0' - 5.0.1 - '5.1' - 5.1.1 references: - type: WEB url: http://freecode.com/projects/feedparser/releases/344371 - type: WEB url: https://code.google.com/p/feedparser/source/detail?r=703&path=/trunk/feedparser/feedparser.py - type: WEB url: https://code.google.com/p/feedparser/source/browse/trunk/NEWS?spec=svn706&r=706 - type: WEB url: http://osvdb.org/81701 - type: ADVISORY url: http://secunia.com/advisories/49256 - type: WEB url: http://www.securityfocus.com/bid/53654 - type: WEB url: https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-0157 - type: ADVISORY url: http://www.mandriva.com/security/advisories?name=MDVSA-2013:118 - type: ADVISORY url: https://github.com/advisories/GHSA-hjf3-r7gw-9rwg aliases: - CVE-2012-2921 - GHSA-hjf3-r7gw-9rwg modified: '2021-08-27T03:22:03.863933Z' published: '2012-05-21T22:55:00Z'