PublicDateAtUSN: 2007-09-04 PublicDate: 2007-09-04 18:17:00 UTC Candidate: CVE-2007-3998 References: https://ubuntu.com/security/notices/USN-549-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3998 Description: The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set. Ubuntu-Description: Notes: kees> http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.63&r2=1.445.2.14.2.64&view=patch kees> 200-string-wordwrap.patch Bugs: Priority: medium Discovered-by: Assigned-to: kees CVSS: upstream_php5: released (5.2.4) dapper_php5: released (5.1.2-1ubuntu3.10) edgy_php5: released (5.1.6-1ubuntu2.7) feisty_php5: released (5.2.1-0ubuntu1.5) gutsy_php5: released (5.2.3-1ubuntu6.1) hardy_php5: not-affected (5.2.4-2ubuntu3) intrepid_php5: not-affected (5.2.4-2ubuntu3) jaunty_php5: not-affected (5.2.4-2ubuntu3) karmic_php5: not-affected (5.2.4-2ubuntu3) devel_php5: not-affected (5.2.4-2ubuntu3) Patches_php4: upstream: http://cvs.php.net/viewcvs.cgi/php-src/ext/standard/string.c?r1=1.445.2.14.2.63&r2=1.445.2.14.2.64&view=patch other: 200-string-wordwrap.patch upstream_php4: released (4.4.8) dapper_php4: ignored (reached end-of-life) edgy_php4: needed (reached end-of-life) feisty_php4: DNE gutsy_php4: DNE hardy_php4: DNE intrepid_php4: DNE jaunty_php4: DNE karmic_php4: DNE devel_php4: DNE