Bug #52885 [Opn->Csd]: PDO_DBLIB does not properly quote char(0)
| From: | ssufficool@php.net | Date: | Sat, 25 Oct 2014 03:15:12 +0000 |
| Subject: | Bug #52885 [Opn->Csd]: PDO_DBLIB does not properly quote char(0) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-188302@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=52885&edit=1
ID: 52885
Updated by: ssufficool@php.net
Reported by: ssufficool@php.net
Summary: PDO_DBLIB does not properly quote char(0)
-Status: Open
+Status: Closed
Type: Bug
Package: PDO DBlib
Operating System: Linux
PHP Version: 5.3SVN-2010-09-19 (SVN)
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of ssufficool
Revision: http://git.php.net/?p=php-src.git;a=commit;h=a1a18fca6e2a1690ea113dc2ebe0e7d22fdc71a0
Log: Fixed Bug #52885 - PDO_DBLIB: Binary data may be truncated
Previous Comments:
------------------------------------------------------------------------
[2010-09-21 01:04:10] ssufficool at gmail dot com
There is a larger issue here to do with unicode code page conversions and the such.
What really needs to be done is to implement the native dblib parameter bindings to stop the
encoding of all parameters as strings which are then interpreted by iconv to the server charset
which may not suport the full range of characters from 0-255.
------------------------------------------------------------------------
[2010-09-19 02:34:18] ssufficool@php.net
Description:
------------
When using bound parameter with char(0), the parameter is truncated. This is a possible SQL
injection flaw in the dblib quote implementation.
Test script:
---------------
$stmt = $pdo->prepare("insert into test(image_field) values(?)");
$blob = file_get_contents("test.jpg");
$stmt->execute(array($blob));
Expected result:
----------------
No error
Actual result:
--------------
invalid statement due to truncation of ASCIIZ string in dblib_handle_quoter
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=52885&edit=1