Bug #54391 [Com]: escapeshellarg strip non-ascii characters
Edit report at https://bugs.php.net/bug.php?id=54391&edit=1
ID: 54391
Comment by: me at paulofreitas dot me
Reported by: c dot madmax at gmail dot com
Summary: escapeshellarg strip non-ascii characters
Status: Open
Type: Bug
Package: Program Execution
Operating System: All Debian and Ubuntu Versions
PHP Version: 5.3.6
Block user comment: N
Private report: N
New Comment:
Test script:
---------------
<?php
$filename = 'résumé.pdf';
var_dump(escapeshellarg($filename));
setlocale(LC_CTYPE, 'en_US.utf8');
var_dump(escapeshellarg($filename));
?>
Test result when executed from CLI:
---------------
string(14) "'résumé.pdf'"
string(14) "'résumé.pdf'"
Test result when executed from Apache:
---------------
// Executed from Apache
string(10) "'rsum.pdf'"
string(14) "'résumé.pdf'"
Which locale to use? Will it works cross-platform? Yeah, that's a very annoying unexpected
behavior.
Previous Comments:
------------------------------------------------------------------------
[2011-03-26 15:35:48] c dot madmax at gmail dot com
This is a different bug!
Bug 44945 is related to utf-8 strings, and the bug is fixed. escapeshellarg() don't remve valid
utf-8 characters.
But escapeshellarg() remove ISO-8959-1 characters!
------------------------------------------------------------------------
[2011-03-26 15:18:54] felipe@php.net
Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php
------------------------------------------------------------------------
[2011-03-26 15:18:43] felipe@php.net
See bug #44945
------------------------------------------------------------------------
[2011-03-26 15:12:53] c dot madmax at gmail dot com
Description:
------------
escapeshellarg() strip non-ascii characters if the LANG environment variable is not set to somthing
like LANG=*.ISO-8959-1 e.g. LANG=en_US.ISO-8959-1
The job of escapeshellarg() is only to escape characters and NOT to remove them!!! The manual say
nothing about removing characters!!!
Removing characters can cause horrible results!!!
It should doesn't matter if a shell arg has a ISO-8959-1 charset or UTF-8 charset or any other
charset, because it is possible that a filename has a ISO-8959-1 charset and a other filename has a
UTF-8 charset!!!
escapeshellarg() should only look for quotes and escape them, and nothing else!!!
PS:
setlocale(LC_ALL, 'en_US.ISO-8959-1') and/or putenv('LANG=en_US.ISO-8959-1')
dosn't fix this problem! And i think even if this work it's not good a solution!
Test script:
---------------
<?php
$path = escapeshellarg('/home/www-data/äöüÃÃÃÃ'); // ISO-8959-1
characters = "\xE4\xF6\xFC\xC4\xD6\xDC\xDF" in hex format
shell_exec(sprintf('rm -fr %s', $path));
echo sprintf('%s removed', $path);
?>
Expected result:
----------------
The test script should remove the folder /home/www-data/äöüÃÃÃà and output:
'/home/www-data/äöüÃÃÃÃ' removed
Actual result:
--------------
The test script remove the folder /home/www-data/ and output
'/home/www-data/' removed
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=54391&edit=1
Thread (9 messages)