VDB
CVE-2007-3998
CVE-2007-3998
PUBLISHED
CVSS 5 MEDIUM
The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a 'chr(0), 0, ""' argument set.
EPSS 2.99% · 86.8th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
2.99%
86.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| debian | debian_linux | 4.0, 3.1 |
| n/a | n/a | n/a |
| canonical | ubuntu_linux | 7.10, 6.10, 7.04 |
| php | php | 4.0.0, 5.0.0 |
Timeline
- Sep 4, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 13, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 4, 2023 EPSS Score
- Jul 19, 2023 EPSS Score
- Sep 10, 2023 EPSS Score
- Dec 25, 2023 EPSS Score
- Apr 8, 2024 EPSS Score
References
- http://secunia.com/advisories/26642 url
- 30288 third-party-advisory
- https://launchpad.net/bugs/173043 url
- oval:org.mitre.oval:def:10603 vdb
- 28658 third-party-advisory
- DSA-1444 vendor-advisory
- GLSA-200710-02 vendor-advisory
- 27864 third-party-advisory
- 26930 third-party-advisory
- RHSA-2007:0889 vendor-advisory
- USN-549-1 vendor-advisory
- DSA-1578 vendor-advisory
- http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm url
- 26838 third-party-advisory
- http://secweb.se/en/advisories/php-wordwrap-vulnerability/ url
- 27377 third-party-advisory
- 27102 third-party-advisory
- ADV-2007-3023 vdb
- http://www.php.net/releases/5_2_4.php url
- RHSA-2007:0890 vendor-advisory
…and 19 more