The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").
{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.909"
}
],
"source": "CPE_RANGE",
"cpe": "cpe:2.3:a:email\\:\\:address_module_project:email\\:\\:address:*:*:*:*:*:perl:*:*"
}