CVE-2007-3998
Publication date 4 September 2007
Last updated 24 July 2024
Ubuntu priority
Description
The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| php4 | ||
| php5 | ||
Notes
kees
http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.63&r2=1.445.2.14.2.64&view=patch 200-string-wordwrap.patch
Patch details
| Package | Patch details |
|---|---|
| php4 |