Bug #68963 [Com]: Error handler output is not binary safe
| From: | hanskrentel at yahoo dot de | Date: | Sun, 05 Jul 2015 21:23:48 +0000 |
| Subject: | Bug #68963 [Com]: Error handler output is not binary safe | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-194143@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68963&edit=1
ID: 68963
Comment by: hanskrentel at yahoo dot de
Reported by: mails at thomasbley dot de
Summary: Error handler output is not binary safe
Status: Open
Type: Bug
Package: *General Issues
Operating System: Ubuntu 14.04.1 LTS
PHP Version: 5.5.21
Block user comment: N
Private report: N
New Comment:
This is for all error messages, e.g.:
trigger_error("foo\0bar");
Previous Comments:
------------------------------------------------------------------------
[2015-01-31 09:30:44] mails at thomasbley dot de
Description:
------------
Accessing undefined object members gives a wrong notice message if the member contains a zero byte.
The problem occurs in real code when request parameters are put as members in controller or request
objects.
Test script:
---------------
<?php
ini_set('error_reporting', E_ALL);
ini_set('display_errors', 1);
$obj = new stdclass();
echo $obj->{"foo\0bar"};
$obj->{"foo\0bar"} = 1;
echo $obj->{"foo\0bar"};
Expected result:
----------------
sapi/cli/php /tmp/test.php
Notice: Undefined property: stdClass::$foobar in /tmp/test.php on line 6
1
Actual result:
--------------
sapi/cli/php /tmp/test.php
Notice: Undefined property: stdClass::$foo in /tmp/test.php on line 6
1
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68963&edit=1