CVE-2007-3998
Publication date 4 September 2007
Last updated 24 July 2024
Ubuntu priority
The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set.
Status
Package | Ubuntu Release | Status |
---|---|---|
php4 | ||
php5 | ||
Notes
kees
http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.63&r2=1.445.2.14.2.64&view=patch 200-string-wordwrap.patch
Patch details
Package | Patch details |
---|---|
php4 |