Bug #67069 [Opn->Dup]: substr_compare() returns incorrect results when using default length
| From: | stas@php.net | Date: | Sun, 13 Apr 2014 23:06:06 +0000 |
| Subject: | Bug #67069 [Opn->Dup]: substr_compare() returns incorrect results when using default length | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-185226@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67069&edit=1
ID: 67069
Updated by: stas@php.net
Reported by: nachms+php at gmail dot com
Summary: substr_compare() returns incorrect results when
using default length
-Status: Open
+Status: Duplicate
Type: Bug
Package: Strings related
Operating System: Linux
PHP Version: 5.5.11
Block user comment: N
Private report: N
New Comment:
Looks like dupe of #67043, at least I am not seeing problems after the fix is applied. Please reopen
if you still see it after updating to latest code.
Previous Comments:
------------------------------------------------------------------------
[2014-04-13 22:42:04] nachms+php at gmail dot com
Description:
------------
PHP in 5.5.11 is returning incorrect results from substr_compare() when length is left as the
default setting. In 5.5.10, it worked correctly.
String checks returning equal when they are not equal is a security hole. Any application checking
the end of a string to equal something, perhaps a user name, password, perhaps the extension on file
types, or other file paths, is now going to think things are equal when they in fact are not.
The documentation for this function: http://php.net/manual/en/function.substr-compare.php
States if the length parameter is not passed:
"The default value is the largest of the length of the str compared to the length of main_str
less the offset."
Or in other words, max(main_str - offset, str), meaning it compares for whatever amount is left over
in in the two strings.
However, in the included test, it seems lenth is always being set to 0.
Test script:
---------------
<?php
echo substr_compare('Cows', 'ws', 2), "\n";
echo substr_compare('Cows', 'ws', -2), "\n";
echo substr_compare('Cows', 'ows', 3), "\n";
echo substr_compare('Cows', 'ows', -3), "\n";
echo substr_compare('Cows', 'aws', 3), "\n";
echo substr_compare('Cows', 'aws', -3), "\n";
Expected result:
----------------
0
0
4
0
18
14
Actual result:
--------------
0
0
0
0
0
0
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67069&edit=1