CVE-2007-3998

The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the breakcharlen variable, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash, or infinite loop) via certain arguments, as demonstrated by a ‘chr(0), 0, ""’ argument set.

Date published : 2007-09-04

http://support.avaya.com/elmodocs2/security/ASA-2007-449.htm

http://www.php.net/ChangeLog-5.php#5.2.4