Bug #71876 [Com]: Memory corruption htmlspecialchars(): charset `*' not supported

From: Date: Fri, 03 Jun 2016 03:32:29 +0000
Subject: Bug #71876 [Com]: Memory corruption htmlspecialchars(): charset `*' not supported
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201413@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71876&edit=1 ID: 71876 Comment by: the_djmaze at hotmail dot com Reported by: the_djmaze at hotmail dot com Summary: Memory corruption htmlspecialchars(): charset `*' not supported Status: Open Type: Bug Package: Strings related Operating System: Fedora 22 PHP Version: 7.0.4 Block user comment: N Private report: N New Comment: Found some websites with the issue: (hit your browser F5 a few times to see it happen) www.modelcity.cz/cz/?page_id=333&album=1&gallery=32 cms.w3host.hu/opencart/index.php?route=product/product&product_id=46 www.suchanoha.cz/?page_id=974&wppa-album=39&wppa-photo=490&wppa-cover=0&wppa-occur=1&wppa-single=1 ubytovani-ledenice.cz/?page_id=14 www.conceptvision.cz/index.php/8-slideshow/15-sli Previous Comments: ------------------------------------------------------------------------ [2016-06-03 03:05:18] the_djmaze at hotmail dot com Also seems to happen on a CentOS server with cPanel EasyApache PHP 5.6.19 [Sun May 29 17:17:00 2016] [error] PHP Warning: html_entity_decode(): charset `@\xef\xbf\xbdf\x03' not supported, assuming utf-8 in /wp-content/plugins/dmsguestbook/admin.php on line 3529 [Sun May 29 17:31:58 2016] [error] PHP Warning: htmlspecialchars(): charset `\x11\x01' not supported, assuming utf-8 in /plugins/system/sef/sef.php on line 49 [Sun May 29 17:32:13 2016] [error] PHP Warning: htmlspecialchars(): charset `Filter object to use.\n\t *\n\t * @var JFilterInput\n\t * @since 11.1\n\t */' not supported, assuming utf-8 in /libraries/cms/application/site.php on line 161 So something in the memory management is broken, i haven't figured out what yet. ------------------------------------------------------------------------ [2016-03-22 23:34:10] the_djmaze at hotmail dot com Looking in ./ext/standard/html.c html_entity_decode() uses get_default_charset() And also suffers from this problem. Then looking at static char *get_default_charset(void) { if (PG(internal_encoding) && PG(internal_encoding)[0]) { return PG(internal_encoding); } else if (SG(default_charset) && SG(default_charset)[0] ) { return SG(default_charset); } return NULL; } In php.ini internal_encoding is not set nor is default_charset. Using ini_get() the first is empty and the latter says "UTF-8" Digging deeper mbstring.c and iconv.c also you the char pointers. mbstring.c only uses it once: return _php_mb_ini_mbstring_internal_encoding_set(get_internal_encoding(), strlen(get_internal_encoding())+1); iconv.c uses it in a lot of places but i don't have this module installed. Maybe later i will to test if this is also affected. ------------------------------------------------------------------------ [2016-03-22 14:39:46] the_djmaze at hotmail dot com Few hours later, and the problem is back. Restart of Apache solved the issue again. ------------------------------------------------------------------------ [2016-03-22 09:18:17] the_djmaze at hotmail dot com After a restart of Apache the problem is gone and not reproducible. I understand this makes it very hard to find. ------------------------------------------------------------------------ [2016-03-22 09:12:04] the_djmaze at hotmail dot com Added a screenshot (with a call of phpinfo() after the code) https://dragonflycms.org/images/php-bug-htmlspecialchars.png Fedora 22 with remi repo $ dnf list installed | grep php php.x86_64 7.0.4-1.fc22.remi php-bcmath.x86_64 7.0.4-1.fc22.remi php-cli.x86_64 7.0.4-1.fc22.remi php-common.x86_64 7.0.4-1.fc22.remi php-devel.x86_64 7.0.4-1.fc22.remi php-gd.x86_64 7.0.4-1.fc22.remi php-gmp.x86_64 7.0.4-1.fc22.remi php-imap.x86_64 7.0.4-1.fc22.remi php-interbase.x86_64 7.0.4-1.fc22.remi php-json.x86_64 7.0.4-1.fc22.remi php-mbstring.x86_64 7.0.4-1.fc22.remi php-mcrypt.x86_64 7.0.4-1.fc22.remi php-mysqlnd.x86_64 7.0.4-1.fc22.remi php-pdo.x86_64 7.0.4-1.fc22.remi php-pear.noarch 1:1.10.1-1.fc22.remi php-pecl-apcu.x86_64 5.1.3-1.fc22.remi.7.0 php-pecl-apcu-bc.x86_64 1.0.3-1.fc22.remi.7.0 php-pecl-gmagick.x86_64 2.0.2-0.3.RC2.fc22.remi.7.0 php-pecl-igbinary.x86_64 1.2.2-0.1.20151217git2b7c703.fc22.remi.7.0 php-pecl-mailparse.x86_64 3.0.1-1.fc22.remi.7.0 php-pecl-memcache.x86_64 3.0.9-0.2.20151130gitfdbd46b.fc22.remi.7.0 php-pecl-memcached.x86_64 3.0.0-0.1.20160217git6ace07d.fc22.remi.7.0 php-pecl-msgpack.x86_64 2.0.1-1.fc22.remi.7.0 php-pecl-uuid.x86_64 1.0.4-6.fc22.remi.7.0 php-pecl-yaml.x86_64 2.0.0-0.6.RC7.fc22.remi.7.0 php-pgsql.x86_64 7.0.4-1.fc22.remi php-process.x86_64 7.0.4-1.fc22.remi php-soap.x86_64 7.0.4-1.fc22.remi php-tidy.x86_64 7.0.4-1.fc22.remi php-xml.x86_64 7.0.4-1.fc22.remi Zend Extension 320151012 Zend Extension Build API320151012,NTS Zend Signal Handling disabled Zend Memory Manager enabled Zend Multibyte Support provided by mbstring zend.assertions 1 zend.detect_unicode On zend.enable_gc On zend.multibyte Off ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71876 -- Edit this bug report at https://bugs.php.net/bug.php?id=71876&edit=1

« previous php.bugs (#201413) next »