Back

MEDIUM

php: hang on numeric value 2.2250738585072011e-308 with x87 fpu

Published Jan 11, 2011

Description

strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows context-dependent attackers to cause a denial of service (infinite loop) via a certain floating-point value in scientific notation, which is not properly handled in x87 FPU registers, as demonstrated using 2.2250738585072011e-308.

Affected products

Remediation

Red Hat statement

This issue leads to a temporary denial of service (high CPU consumption) when a PHP script handles numeric values from untrusted user input. It does not affect the versions of PHP as shipped with Red Hat Enterprise Linux 3, 4 or 5. It did affect the PHP 5.3 (php53) package on Red Hat Enterprise Linux 5.

Metrics

Weaknesses (1)

References (32)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 11, 2011
Updated Feb 13, 2025
Reserved Jan 3, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Dec 30, 2010