CVE-2011-1156: Input Validation
Published Apr 11, 2011
·Updated
feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0.1 allows remote attackers to cause a denial of service (application crash) via a malformed DOCTYPE declaration.
Affected Software
11 affected componentsFixes available
pip/feedparser>=4.1<5.0.1
5.0.1
Mark Pilgrim Feedparser<=5.0
Mark Pilgrim Feedparser=3.0
Mark Pilgrim Feedparser=3.0.1
Mark Pilgrim Feedparser=3.1
Mark Pilgrim Feedparser=3.2
Mark Pilgrim Feedparser=3.3
Mark Pilgrim Feedparser=4.0
Mark Pilgrim Feedparser=4.0.1
Mark Pilgrim Feedparser=4.0.2
Mark Pilgrim Feedparser=4.1
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Apr 11, 2011
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Data Sourced
via NVD·06:55 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 23, 2018
Advisory Published
via GitHub·07:50 PM
Frequently Asked Questions
1
What is the severity of CVE-2011-1156?
The severity of CVE-2011-1156 is rated as high, with a score of 7.5 on the CVSS scale.
2
What type of vulnerability is CVE-2011-1156?
CVE-2011-1156 is classified as a denial of service vulnerability due to input validation issues in feedparser.py.
3
How do I fix CVE-2011-1156?
To fix CVE-2011-1156, you should update to Universal Feed Parser version 5.0.1 or later, which includes a patch for this vulnerability.
4
What application is affected by CVE-2011-1156?
CVE-2011-1156 affects the Universal Feed Parser, commonly known as feedparser or python-feedparser.
5
Can CVE-2011-1156 be exploited remotely?
Yes, CVE-2011-1156 can be exploited remotely by attackers through the use of a malformed DOCTYPE declaration.