If you use the wordwrap() function on user-supplied input, a specially-crafted input can overflow the allocated buffer and overwrite the heap. Exploit looks very difficult, but still theoretically possible. http://marc.theaimsgroup.com/?l=bugtraq&m=104102689503192 http://bugs.php.net/bug.php?id=20927