#16895 [Asn->]: Bad char encoding
| From: | yohgaki@php.net | Date: | Sun, 28 Jul 2002 10:55:04 +0000 |
| Subject: | #16895 [Asn->]: Bad char encoding | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-15440@lists.php.net to get a copy of this message | ||
ID: 16895
Updated by: yohgaki@php.net
Reported By: benoit.sibaud@rd.francetelecom.com
-Status: Assigned
+Status: Won't fix
Bug Type: PostgreSQL related
Operating System: GNU/Linux
PHP Version: 4.1.2
Assigned To: yohgaki
New Comment:
Since this behavior occurs in libpq (PostgreSQL provided C programming
interface), there is nothing much we can do that.
Please update your PostgreSQL sever to 7.2.1 or later.
Previous Comments:
------------------------------------------------------------------------
[2002-06-20 20:28:34] yohgaki@php.net
Just a comment.
Those who are concerned about this problem, upgrade your PostgreSQL to
7.2.1 or later.
------------------------------------------------------------------------
[2002-04-29 03:45:49] benoit.sibaud@rd.francetelecom.com
Cf
http://lists.debian.org/debian-security/2002/debian-security-200204/msg00328.html
A bad char encoding between PHP and PostgreSQL (don't know which is
guilty here), followed by a bug in SQL queries in PostgreSQL can lead
to execute any SQL request.
Sample code here:
%<----------------------------------------
$conn = pg_connect("dbname=" . BASE_DOC . " port=" . BASE_PORT
. " user=" . BASE_USER);
$var="é\'; BAD REQUEST";
pg_exec($conn, "SET client_encoding = 'LATIN1'");
$request = "SELECT col FROM tab WHERE col='" . addslashes($var) .
"'";
%<----------------------------------------
See Debian-security archive for more details. Already tested on a
Debian Woody with PHP-cgi 4.1.2 (+php4-pgsql+php4-pear).
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=16895&edit=1