PT-2007-5215 · Php+1 · Php+1

Published

2007-09-04

·

Updated

2018-10-26

·

CVE-2007-3998

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: PHP versions prior to 4.4.8 PHP versions prior to 5.2.4
Description: The issue is related to the wordwrap function, which does not properly utilize the breakcharlen variable. This allows remote attackers to cause a denial of service, resulting in a divide-by-zero error, application crash, or infinite loop, by providing certain arguments, such as a chr(0), 0, "" argument set.
Recommendations: For PHP versions prior to 4.4.8, update to version 4.4.8 or later. For PHP versions prior to 5.2.4, update to version 5.2.4 or later.

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-3998
DSA-1444-1
DSA-1578-1
DTSA-61-1
RHSA-2007:0889
RHSA-2007:0890
RHSA-2007:0891
RHSA-2007:0917
RHSA-2007_0890

Affected Products

Php
Red Hat