Bug #43225 [Com]: fputcsv incorrectly handles cells ending in \ followed by "

From: Date: Wed, 16 Sep 2015 04:33:27 +0000
Subject: Bug #43225 [Com]: fputcsv incorrectly handles cells ending in \ followed by "
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196033@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=43225&edit=1 ID: 43225 Comment by: plentysu at kkbox dot com Reported by: ed at bronto dot com Summary: fputcsv incorrectly handles cells ending in \ followed by " Status: Re-Opened Type: Bug Package: Filesystem function related Operating System: Centos PHP Version: 5.2.4 Block user comment: N Private report: N New Comment: One thinking to disable escape method: fputcsv($handle, $array, ',', '"', "\0") Previous Comments: ------------------------------------------------------------------------ [2015-07-25 22:14:45] marc at ermshaus dot org The issues with PHP’s CSV functions also seem to be exploitable. <?php $handle = fopen('php://memory', 'w+b'); fputcsv($handle, [ 'foo bar\\', # 1 'baz quz', # 2 'x', # 3 'y', # 4 'z', # 5 'foo\\\\",bar' # 6 ]); rewind($handle); var_dump(fgetcsv($handle)); // array(6) { // [0]=> string(18) "foo bar\",baz quz"" # 1 // [1]=> string(1) "x" # 2 (was # 3) // [2]=> string(1) "y" # 3 (was # 4) // [3]=> string(1) "z" # 4 (was # 5) // [4]=> string(5) "foo\\" # 5 // [5]=> string(4) "bar"" # 6 // } 3v4l.org: http://3v4l.org/LTnC1 ------------------------------------------------------------------------ [2014-09-17 12:46:13] lbarnaud@php.net To summarize the related bugs: fputcsv() seems to be using inconsistent and broken escaping of the enclosing char (") : - " followed by \ are not escaped - " not followed by \ are escaped by doubling them (e.g. " becomes ""); leading to inconsistent escaping method - \ themselves are not escaped, leading to generation of invalid CSV if a field is terminated by \: "foo bar\",baz - With the input \\", the " is still considered to be escaped Due to this combinaison of bugs, it is impossible to parse the CSV generated by the following call: fputcsv(STDOUT, ['foo\"bar', 'foo""bar', 'foo bar\\']); Output is: "foo\"bar","foo""""bar","foo bar\" Trying to parse this with a parser using the doubled-char escaping method will break on the first field. Trying to parse this with a parser using the backslash escaping method will break on the 2nd and 3rd fields. Trying to parse this with a parser allowing both methods will break on the 3rd field. Without the 3rd field, parsing this CSV document would result in loss of information (some \ or " from the original input would be lost). ------------------------------------------------------------------------ [2014-08-21 23:55:57] maris dot radu+phpnet at gmail dot com Just not to confuse people, aharvey@php.net said it's fixed in "5.3.22 and 5.4.12", but in fact I tested in 5.4.31 and it's not fixed. Looking at the patch commit it seems it's tagged with php-5.6.0beta4, so I guess will only be available in 5.6. ------------------------------------------------------------------------ [2013-01-15 09:43:18] aharvey@php.net Sadly, that was a classic case of fixing one thing and breaking another. Reopening, and unassigning myself. ------------------------------------------------------------------------ [2013-01-15 07:35:00] aharvey@php.net Fixed in 5.3.22 and 5.4.12: https://github.com/php/php-src/commit/9b5cb0e8059b1e8bec096067491ed8d75f878938 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=43225 -- Edit this bug report at https://bugs.php.net/bug.php?id=43225&edit=1

« previous php.bugs (#196033) next »