PT-2007-5215 · Php+1 · Php+1
Published
2007-09-04
·
Updated
2018-10-26
·
CVE-2007-3998
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
PHP versions prior to 4.4.8
PHP versions prior to 5.2.4
Description:
The issue is related to the
wordwrap function, which does not properly utilize the breakcharlen variable. This allows remote attackers to cause a denial of service, resulting in a divide-by-zero error, application crash, or infinite loop, by providing certain arguments, such as a chr(0), 0, "" argument set.Recommendations:
For PHP versions prior to 4.4.8, update to version 4.4.8 or later.
For PHP versions prior to 5.2.4, update to version 5.2.4 or later.
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php
Red Hat