CVE-2010-4645
Publication date 11 January 2011
Last updated 24 July 2024
Ubuntu priority
strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.
Notes
sbeattie
unabele to reproduce on 9.10 and before; however, the code in question looks like it ought to be vulnerable. Looking at the compiler flag differences between lucid and karmic's builds didn't show any obvious reason why karmic wouldn't be affected. Released an update for all releases anyway.
References
Related Ubuntu Security Notices (USN)
- USN-1042-1
- PHP vulnerabilities
- 11 January 2011