Bug #68031 [Opn->Fbk]: htmlspecialchars returns empty string, sometimes
| From: | requinix@php.net | Date: | Wed, 17 Sep 2014 17:41:35 +0000 |
| Subject: | Bug #68031 [Opn->Fbk]: htmlspecialchars returns empty string, sometimes | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187572@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68031&edit=1
ID: 68031
Updated by: requinix@php.net
Reported by: pfenderd at bellsouth dot net
Summary: htmlspecialchars returns empty string, sometimes
-Status: Open
+Status: Feedback
Type: Bug
Package: Filter related
Operating System: Linux
PHP Version: 5.5.16
Block user comment: N
Private report: N
New Comment:
Need actual source code, not just the output.
I refreshed a few times and each time it worked correctly: string was intact and unchanged (except
for a couple "s that were converted to "s).
Previous Comments:
------------------------------------------------------------------------
[2014-09-17 15:33:59] pfenderd at bellsouth dot net
The text that caused the problem was pure ASCII text and had no UTF-8 characters in it.
Test case at http://dayspeak.net/test_php_bug_htmlspecialchars.php
This simple test case failed to show the problem (worked properly).
The fact that I could work around the problem by moving the problem-causing assignment down several
lines of code indicates to me that the real problem is not in the htmlspecialchars() function itself
but in the PHP script processor.
------------------------------------------------------------------------
[2014-09-17 05:18:09] rasmus@php.net
Likely because you are getting invalid utf-8. Either specify the correct charset of your input to
your htmlspecialchars() call, or filter out invalid utf-8 before the call. Outputting invalid UTF-8
is a security risk so previous your PHP 5.3-based application was vulnerable and now it isn't.
------------------------------------------------------------------------
[2014-09-16 20:17:02] requinix@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a short but complete example script to be able to reproduce
this bug ourselves.
A proper reproducing script starts with <?php and ends with ?>,
is max. 10-20 lines long and does not require any external
resources such as databases, etc. If the script requires a
database to demonstrate the issue, please make sure it creates
all necessary tables, stored procedures etc.
Please avoid embedding huge scripts into the report.
------------------------------------------------------------------------
[2014-09-16 19:24:23] pfenderd at bellsouth dot net
Description:
------------
Occasionally,htmlspecialchars() returns an empty string value.
It is consistent for certain string values and not a random problem.
The string is usually long (several 100 chars).
The problem did not exist in version 5.3.14 but does in later versions of 5.4 and 5.5.16.
In a list of assignments to variables using htmlspecialchars(), it fails on the 5th of 10. The
others always work properly, but the other string values are always much shorter than the one that
fails.
I created a simple test script, but the script always works.
The problem is probably affected by the other code surrounding the problem statement.
This is a serious problem because the code is used to maintain values in a database for a website
and is not able to do so when database values cannot be seen in a management form.
NOTE:
I found a work-around solution to the problem by moving the line of code with the problem farther
down the list of assignments. So it may not be a problem directly with htmlspecialchars(), but with
the PHP script processor.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68031&edit=1