[Bug 697181] Re: DoS: Infinite loop processing 2.2250738585072011e-308

Paul Sladen ubuntu at paul.sladen.org
Fri Jan 7 02:48:33 UTC 2011


** Bug watch added: Red Hat Bugzilla #667806
   https://bugzilla.redhat.com/show_bug.cgi?id=667806

** Also affects: php5 (Fedora) via
   https://bugzilla.redhat.com/show_bug.cgi?id=667806
   Importance: Unknown
       Status: Unknown

** CVE added: http://www.cve.mitre.org/cgi-
bin/cvename.cgi?name=2010-4645

** Description changed:

  Binary package hint: php5
  
  Processing certain textual forms of MAX_FLOAT leads to an infinite
  loop/hang/DoS:
  
    php -r "print 2.2250738585072011e-308;"
  
  hangs indefinitely, whereas:
  
    php -r "print 2.2250738585072010e-308;"
  
  returns immediately.
  
  Confirmed for natty/php5-cli=5.3.3-1ubuntu11
+ 
+ Fixed in new upstream releases:
+ 
+   http://www.php.net/ChangeLog-5.php#5.3.4
+   http://www.php.net/releases/5_2_17.php

** Bug watch added: Debian Bug tracker #609007
   http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=609007

** Also affects: php5 (Debian) via
   http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=609007
   Importance: Unknown
       Status: Unknown

-- 
You received this bug notification because you are a member of Ubuntu
Server Team, which is subscribed to php5 in ubuntu.
https://bugs.launchpad.net/bugs/697181

Title:
  DoS: Infinite loop processing 2.2250738585072011e-308



More information about the Ubuntu-server-bugs mailing list