CVE-2007-3998

Publication date

2007-09-04 18:00:00

Family

mitre

State

PUBLISHED

Description

The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a chr(0), 0, "" argument set.