Bug #43784 [Asn->Csd]: escapeshellarg removes % from given string
| From: | ajf@php.net | Date: | Fri, 09 Jan 2015 01:04:05 +0000 |
| Subject: | Bug #43784 [Asn->Csd]: escapeshellarg removes % from given string | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189812@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=43784&edit=1
ID: 43784
Updated by: ajf@php.net
Reported by: bate@php.net
Summary: escapeshellarg removes % from given string
-Status: Assigned
+Status: Closed
Type: Bug
Package: Program Execution
Operating System: Windows
PHP Version: 6CVS-2008-01-08 (snap)
Assigned To: scottmac
Block user comment: N
Private report: N
New Comment:
Thank you for your bug report. This issue has already been fixed
in the latest released version of PHP, which you can download at
http://www.php.net/downloads.php
I'm using 5.6 and this is fixed. I assume it was fixed a while ago, but I don't know which
version.
Previous Comments:
------------------------------------------------------------------------
[2008-07-20 16:09:13] pajoye@php.net
Assigned to Scott to see if this problem can't be solved with the one describe in #43261
------------------------------------------------------------------------
[2008-01-08 09:10:24] derick@php.net
I'm assigning it to you ilia, as you made the original patch as well.
------------------------------------------------------------------------
[2008-01-08 09:10:01] derick@php.net
This is because of the following commit:
http://cvs.php.net/viewvc.cgi/php-src/ext/standard/exec.c?r1=1.84.2.13&r2=1.84.2.14
which was a reaction to a security bulletin. However, just stripping out the % is not the solution,
as it can only be used to access env vars *outside* strings, and with a matching %. However, just
stripping them out is not a good solution as it hinders real life use of it like in this example.
------------------------------------------------------------------------
[2008-01-08 09:04:37] bate@php.net
Description:
------------
escapeshellarg(string) removes all % out of it. This results in a non working version for arguments
that requires % for formating.
ie. imagick identify.exe
identify -format "%m" myimage.png
Reproduce code:
---------------
<?php
echo escapeshellarg('%m %f %v');
Expected result:
----------------
'%m %f %v'
Actual result:
--------------
' m f v'
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=43784&edit=1