Bug #43784 [Asn->Csd]: escapeshellarg removes % from given string

From: Date: Fri, 09 Jan 2015 01:04:05 +0000
Subject: Bug #43784 [Asn->Csd]: escapeshellarg removes % from given string
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189812@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=43784&edit=1 ID: 43784 Updated by: ajf@php.net Reported by: bate@php.net Summary: escapeshellarg removes % from given string -Status: Assigned +Status: Closed Type: Bug Package: Program Execution Operating System: Windows PHP Version: 6CVS-2008-01-08 (snap) Assigned To: scottmac Block user comment: N Private report: N New Comment: Thank you for your bug report. This issue has already been fixed in the latest released version of PHP, which you can download at http://www.php.net/downloads.php I'm using 5.6 and this is fixed. I assume it was fixed a while ago, but I don't know which version. Previous Comments: ------------------------------------------------------------------------ [2008-07-20 16:09:13] pajoye@php.net Assigned to Scott to see if this problem can't be solved with the one describe in #43261 ------------------------------------------------------------------------ [2008-01-08 09:10:24] derick@php.net I'm assigning it to you ilia, as you made the original patch as well. ------------------------------------------------------------------------ [2008-01-08 09:10:01] derick@php.net This is because of the following commit: http://cvs.php.net/viewvc.cgi/php-src/ext/standard/exec.c?r1=1.84.2.13&r2=1.84.2.14 which was a reaction to a security bulletin. However, just stripping out the % is not the solution, as it can only be used to access env vars *outside* strings, and with a matching %. However, just stripping them out is not a good solution as it hinders real life use of it like in this example. ------------------------------------------------------------------------ [2008-01-08 09:04:37] bate@php.net Description: ------------ escapeshellarg(string) removes all % out of it. This results in a non working version for arguments that requires % for formating. ie. imagick identify.exe identify -format "%m" myimage.png Reproduce code: --------------- <?php echo escapeshellarg('%m %f %v'); Expected result: ---------------- '%m %f %v' Actual result: -------------- ' m f v' ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=43784&edit=1

« previous php.bugs (#189812) next »