Bug #69217 [NEW]: b_convert_encoding() passes 0x80 as valid ASCII and ISO-8859-1 code
| From: | salsi at icosaedro dot it | Date: | Wed, 11 Mar 2015 03:27:18 +0000 |
| Subject: | Bug #69217 [NEW]: b_convert_encoding() passes 0x80 as valid ASCII and ISO-8859-1 code | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-191301@lists.php.net to get a copy of this message | ||
From: salsi at icosaedro dot it
Operating system: Slackware 14.1, Windows VISTA
PHP version: Irrelevant
Package: mbstring related
Bug Type: Bug
Bug description:b_convert_encoding() passes 0x80 as valid ASCII and ISO-8859-1 code
Description:
------------
mb_convert_encoding() does not recognize invalid bytes from ill formed
ASCII and ISO-8859-1 encoded binary string. It seems that this 0x80 byte
be blindly converted to its corresponding 2-bytes UTF-8 sequence 0xC2
0x80. Instead, converting from UTF-8 in itself the error is detected.
Although not stated anywhere, mb_convert_encoding() should guarantee
that either the resulting output string be perfectly compliant with the
requested expected encoding, or it must fail with error. Returning
unexpected results may have safety and security consequences.
Tested on:
- PHP 5.7.0-dev Slackware Linux 14.1
- PHP 5.5.16 Windows VISTA
Test script:
---------------
<?php
error_reporting(PHP_INT_MAX);
ini_set("mbstring.substitute_character", (string) ord("X"));
ini_set("mbstring.strict_detection", "1"); // no effect
// bytes 0x80-0xff are not valid ASCII:
echo 1, rawurlencode(mb_convert_encoding("\x80", "UTF-8", "ASCII")) .
"\n";
// bytes 0x80-0x9f are not valid ISO-8859-1:
echo 2, rawurlencode(mb_convert_encoding("\x80", "UTF-8",
"ISO-8859-1"))
. "\n";
echo 3, rawurlencode(mb_convert_encoding("\x80", "UTF-8", "UTF-8")) .
"\n";
Expected result:
----------------
1X
2X
3X
Actual result:
--------------
1%C2%80
2%C2%80
3X
--
Edit bug report at https://bugs.php.net/bug.php?id=69217&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69217&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69217&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69217&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69217&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69217&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69217&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69217&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69217&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69217&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69217&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69217&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69217&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69217&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69217&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69217&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69217&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69217&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69217&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69217&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69217&r=mysqlcfg