Bug #71876 [Fbk]: Memory corruption htmlspecialchars(): charset `*' not supported

From: Date: Sun, 05 Jun 2016 02:31:07 +0000
Subject: Bug #71876 [Fbk]: Memory corruption htmlspecialchars(): charset `*' not supported
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201449@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71876&edit=1

 ID:                 71876
 Updated by:         yohgaki@php.net
 Reported by:        the_djmaze at hotmail dot com
 Summary:            Memory corruption htmlspecialchars(): charset `*'
                     not supported
 Status:             Feedback
 Type:               Bug
 Package:            Strings related
 Operating System:   Fedora 22
 PHP Version:        7.0.4
 Block user comment: N
 Private report:     N

 New Comment:

It sounds like zend_string handling issue. i.e. String is released, but pointer points to
zend_string buffer. I've seen this type of bugs in 5.x to 7.0 transition. 

I cannot reproduce this, if you could narrow down specific condition reproducing this, I'll
look into it.


Previous Comments:
------------------------------------------------------------------------
[2016-06-04 20:58:33] yohgaki@php.net

What is the default_charset setting? i.e. var_dump(ini_get('default_charset'));

------------------------------------------------------------------------
[2016-06-03 03:32:28] the_djmaze at hotmail dot com

Found some websites with the issue: (hit your browser F5 a few times to see it happen)

www.modelcity.cz/cz/?page_id=333&album=1&gallery=32
cms.w3host.hu/opencart/index.php?route=product/product&product_id=46

www.suchanoha.cz/?page_id=974&wppa-album=39&wppa-photo=490&wppa-cover=0&wppa-occur=1&wppa-single=1

ubytovani-ledenice.cz/?page_id=14

www.conceptvision.cz/index.php/8-slideshow/15-sli

------------------------------------------------------------------------
[2016-06-03 03:05:18] the_djmaze at hotmail dot com

Also seems to happen on a CentOS server with cPanel EasyApache PHP 5.6.19

[Sun May 29 17:17:00 2016] [error] PHP Warning:  html_entity_decode(): charset
`@\xef\xbf\xbdf\x03' not supported, assuming utf-8 in
/wp-content/plugins/dmsguestbook/admin.php on line 3529
[Sun May 29 17:31:58 2016] [error] PHP Warning:  htmlspecialchars(): charset `\x11\x01' not
supported, assuming utf-8 in /plugins/system/sef/sef.php on line 49
[Sun May 29 17:32:13 2016] [error] PHP Warning:  htmlspecialchars(): charset `Filter object to
use.\n\t *\n\t * @var    JFilterInput\n\t * @since  11.1\n\t */' not supported, assuming utf-8
in /libraries/cms/application/site.php on line 161

So something in the memory management is broken, i haven't figured out what yet.

------------------------------------------------------------------------
[2016-03-22 23:34:10] the_djmaze at hotmail dot com

Looking in ./ext/standard/html.c html_entity_decode() uses get_default_charset()
And also suffers from this problem.

Then looking at
static char *get_default_charset(void) {
	if (PG(internal_encoding) && PG(internal_encoding)[0]) {
		return PG(internal_encoding);
	} else if (SG(default_charset) && SG(default_charset)[0] ) {
		return SG(default_charset);
	}
	return NULL;
}

In php.ini internal_encoding is not set nor is default_charset.
Using ini_get() the first is empty and the latter says "UTF-8"

Digging deeper mbstring.c and iconv.c also you the char pointers.

mbstring.c only uses it once:
return _php_mb_ini_mbstring_internal_encoding_set(get_internal_encoding(),
strlen(get_internal_encoding())+1);

iconv.c uses it in a lot of places but i don't have this module installed.
Maybe later i will to test if this is also affected.

------------------------------------------------------------------------
[2016-03-22 14:39:46] the_djmaze at hotmail dot com

Few hours later, and the problem is back.
Restart of Apache solved the issue again.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71876


--
Edit this bug report at https://bugs.php.net/bug.php?id=71876&edit=1


Thread (17 messages)

« previous php.bugs (#201449) next »