Bug #60965 [Ctl]: Buffer overflow on htmlspecialchars/entities with $double=false

From: Date: Fri, 03 Feb 2012 17:03:40 +0000
Subject: Bug #60965 [Ctl]: Buffer overflow on htmlspecialchars/entities with $double=false
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-167113@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60965&edit=1

 ID:                 60965
 Updated by:         rasmus@php.net
 Reported by:        cataphract@php.net
 Summary:            Buffer overflow on htmlspecialchars/entities with
                     $double=false
 Status:             Critical
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Any
 PHP Version:        5.4SVN-2012-02-03 (SVN)
 Assigned To:        cataphract
 Block user comment: N
 Private report:     N

 New Comment:

This is 5.4-only?


Previous Comments:
------------------------------------------------------------------------
[2012-02-03 10:48:29] cataphract@php.net

Description:
------------
Long entities can cause a buffer overflow because the loop only guarantees 40 bytes available in
beginning.

Test script:
---------------
<?php
echo
htmlspecialchars('"""""""""""""""""""""""""""""""""""""""""""""&#x000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005;',
ENT_QUOTES, 'UTF-8', false), "\n";



------------------------------------------------------------------------



-- 
Edit this bug report at https://bugs.php.net/bug.php?id=60965&edit=1


Thread (7 messages)

« previous php.bugs (#167113) next »