Bug #52885 [Com]: PDO_DBLIB does not properly quote char(0)

From: Date: Tue, 05 Jul 2016 05:39:33 +0000
Subject: Bug #52885 [Com]: PDO_DBLIB does not properly quote char(0)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202054@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=52885&edit=1 ID: 52885 Comment by: chris dot kingslynne at gmail dot com Reported by: ssufficool@php.net Summary: PDO_DBLIB does not properly quote char(0) Status: Closed Type: Bug Package: PDO DBlib Operating System: Linux PHP Version: 5.3SVN-2010-09-19 (SVN) Block user comment: N Private report: N New Comment: Hi, This change has completely broken Unicode _text_ support in pdo_dblib using FreeTDS. This change causes binary encoded UTF-8 data to be sent to the backend that only accepts UTF-16. It is quite incompatible with PHP 5.5 behaviour and a major BC break! Can we please discuss reverting this change? Chris Previous Comments: ------------------------------------------------------------------------ [2014-11-18 20:34:59] ab@php.net Automatic comment on behalf of ssufficool Revision: http://git.php.net/?p=php-src.git;a=commit;h=a1a18fca6e2a1690ea113dc2ebe0e7d22fdc71a0 Log: Fixed Bug #52885 - PDO_DBLIB: Binary data may be truncated ------------------------------------------------------------------------ [2014-10-25 03:15:12] ssufficool@php.net Automatic comment on behalf of ssufficool Revision: http://git.php.net/?p=php-src.git;a=commit;h=a1a18fca6e2a1690ea113dc2ebe0e7d22fdc71a0 Log: Fixed Bug #52885 - PDO_DBLIB: Binary data may be truncated ------------------------------------------------------------------------ [2010-09-21 01:04:10] ssufficool at gmail dot com There is a larger issue here to do with unicode code page conversions and the such. What really needs to be done is to implement the native dblib parameter bindings to stop the encoding of all parameters as strings which are then interpreted by iconv to the server charset which may not suport the full range of characters from 0-255. ------------------------------------------------------------------------ [2010-09-19 02:34:18] ssufficool@php.net Description: ------------ When using bound parameter with char(0), the parameter is truncated. This is a possible SQL injection flaw in the dblib quote implementation. Test script: --------------- $stmt = $pdo->prepare("insert into test(image_field) values(?)"); $blob = file_get_contents("test.jpg"); $stmt->execute(array($blob)); Expected result: ---------------- No error Actual result: -------------- invalid statement due to truncation of ASCIIZ string in dblib_handle_quoter ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=52885&edit=1

« previous php.bugs (#202054) next »