CVE-2010-4645

NameCVE-2010-4645
Descriptionstrtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
php5sourcelenny(not affected)
php5source(unstable)5.3.3-7high

Notes

lenny10 includes a test for the bug. With lenny's toolchain
and settings, the bug can't be reproduced.

Search for package or bug name: Reporting problems