CVE-2007-3998

Description

From CVE.org

The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set.

Statement

This issue did not affect the versions of PHP as shipped with Red Hat Enterprise Linux 2.1.

Frequently Asked Questions

Want to get errata notifications? Sign up here.