Bug #52885 [Opn->Csd]: PDO_DBLIB does not properly quote char(0)

From: Date: Sat, 25 Oct 2014 03:15:12 +0000
Subject: Bug #52885 [Opn->Csd]: PDO_DBLIB does not properly quote char(0)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-188302@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52885&edit=1 ID: 52885 Updated by: ssufficool@php.net Reported by: ssufficool@php.net Summary: PDO_DBLIB does not properly quote char(0) -Status: Open +Status: Closed Type: Bug Package: PDO DBlib Operating System: Linux PHP Version: 5.3SVN-2010-09-19 (SVN) Block user comment: N Private report: N New Comment: Automatic comment on behalf of ssufficool Revision: http://git.php.net/?p=php-src.git;a=commit;h=a1a18fca6e2a1690ea113dc2ebe0e7d22fdc71a0 Log: Fixed Bug #52885 - PDO_DBLIB: Binary data may be truncated Previous Comments: ------------------------------------------------------------------------ [2010-09-21 01:04:10] ssufficool at gmail dot com There is a larger issue here to do with unicode code page conversions and the such. What really needs to be done is to implement the native dblib parameter bindings to stop the encoding of all parameters as strings which are then interpreted by iconv to the server charset which may not suport the full range of characters from 0-255. ------------------------------------------------------------------------ [2010-09-19 02:34:18] ssufficool@php.net Description: ------------ When using bound parameter with char(0), the parameter is truncated. This is a possible SQL injection flaw in the dblib quote implementation. Test script: --------------- $stmt = $pdo->prepare("insert into test(image_field) values(?)"); $blob = file_get_contents("test.jpg"); $stmt->execute(array($blob)); Expected result: ---------------- No error Actual result: -------------- invalid statement due to truncation of ASCIIZ string in dblib_handle_quoter ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=52885&edit=1

« previous php.bugs (#188302) next »