Bug #66797 [Opn->Ana]: mb_substr only takes 32-bit signed integer
| From: | cmb@php.net | Date: | Tue, 30 Aug 2016 11:43:14 +0000 |
| Subject: | Bug #66797 [Opn->Ana]: mb_substr only takes 32-bit signed integer | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203677@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66797&edit=1
ID: 66797
Updated by: cmb@php.net
Reported by: astewart at online-buddies dot com
Summary: mb_substr only takes 32-bit signed integer
-Status: Open
+Status: Analyzed
Type: Bug
Package: mbstring related
Operating System: MacOS 10.9.2; CentOS 6.4
PHP Version: 5.4.25
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Thanks for reporting this issue.
The actual problem is that mbfl_substr() defines its
from and
len parameters to be int. Therefore truncation is possible.
Previous Comments:
------------------------------------------------------------------------
[2014-02-28 15:40:27] astewart at online-buddies dot com
Description:
------------
mb_substr takes an int argument for length, but does not accept all integers on a 64-bit compiled
PHP. Instead, the number is treated as -(1<<31), and the string is therefore truncated to zero
length.
Test script:
---------------
<?php
assert('"1" == mb_substr("1", 0, PHP_INT_MAX)');
Expected result:
----------------
No output
Actual result:
--------------
PHP Warning: assert(): Assertion ""1" == mb_substr("1", 0,
PHP_INT_MAX)" failed in t.php on line 2
PHP Stack trace:
PHP 1. {main}() t.php:0
PHP 2. assert() t.php:2
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66797&edit=1