Bug #67864 [Opn->Csd]: escapeshellarg incorrectly escapes single quotes

From: Date: Tue, 19 Aug 2014 18:39:44 +0000
Subject: Bug #67864 [Opn->Csd]: escapeshellarg incorrectly escapes single quotes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187187@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67864&edit=1 ID: 67864 User updated by: Laurent dot Lyaudet at gmail dot com Reported by: Laurent dot Lyaudet at gmail dot com Summary: escapeshellarg incorrectly escapes single quotes -Status: Open +Status: Closed Type: Bug Package: *General Issues Operating System: Linux PHP Version: master-Git-2014-08-19 (Git) Block user comment: N Private report: N New Comment: My bad, I forgot that the shell concatenates single quotes escaped string, and that : touch test\ \'\"\ test touch 'test '\''" test' touch "test '\" test" all work and are equivalent but touch 'test \'" test' does not work. I wonder if it wouldn't be simpler and safer for escapeshellarg to escape args using double quotes instead of simple quotes to encapsulate the string. Best regards, Laurent Lyaudet Previous Comments: ------------------------------------------------------------------------ [2014-08-19 13:08:02] Laurent dot Lyaudet at gmail dot com Description: ------------ Hi, Single quotes are not properly escaped by escapeshellargs. The correction is trivial. Current source code in exec.c is 363 switch (str[x]) { 364 #ifdef PHP_WIN32 365 case '"': 366 case '%': 367 cmd->val[y++] = ' '; 368 break; 369 #else 370 case '\'': 371 cmd->val[y++] = '\''; 372 cmd->val[y++] = '\\'; 373 cmd->val[y++] = '\''; 374 #endif 375 /* fall-through */ 376 default: 377 cmd->val[y++] = str[x]; 378 } line 371 should be removed and a line with 'break;' should be added between lines 373 and 374. Correct source code should be 363 switch (str[x]) { 364 #ifdef PHP_WIN32 365 case '"': 366 case '%': 367 cmd->val[y++] = ' '; 368 break; 369 #else 370 case '\'': 371 cmd->val[y++] = '\\'; 372 cmd->val[y++] = '\''; 373 break; 374 #endif 375 /* fall-through */ 376 default: 377 cmd->val[y++] = str[x]; 378 } Best regards, Laurent Lyaudet Test script: --------------- root@wheezyDEVLaurent:~# php <?php echo "\n", escapeshellarg('\''), "\n"; ?> ''\''' root@wheezyDEVLaurent:~# Expected result: ---------------- '\'' Actual result: -------------- ''\''' ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67864&edit=1

« previous php.bugs (#187187) next »