#3812 [Opn->Csd]: urlencode not bin-safe
| From: | hholzgra@php.net | Date: | Mon, 30 Sep 2002 22:53:55 +0000 |
| Subject: | #3812 [Opn->Csd]: urlencode not bin-safe | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-20809@lists.php.net to get a copy of this message | ||
ID: 3812
Updated by: hholzgra@php.net
Reported By: baumert@pilot-webdesign.de
-Status: Open
+Status: Closed
Bug Type: Reproducible Crash
Operating System: Linux Redhat 5.2, 2.0.36, glibc2
PHP Version: 3.0.15
New Comment:
this is ok in php 4.2.3 code
Previous Comments:
------------------------------------------------------------------------
[2000-03-12 08:06:24] baumert@pilot-webdesign.de
The urlencode function is not binary safe. It retrieves the length of
the string to encode as a parameter,
then uses strlen to allocate the new buffer. Strlen returns wrong
length for the bin-string.
After that, the len-parameter is used to fill the buffer => a
buffer-overwrite occurs.
php 4 beta 4 pl1:
change line 241 from
str = (unsigned char *) emalloc(3 * strlen(s) + 1);
to
str = (unsigned char *) emalloc(3 * len + 1);
php 3.15
change line 242 from
str = (unsigned char *) emalloc(3 * strlen(s) + 1);
to
str = (unsigned char *) emalloc(3 * len + 1);
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=3812&edit=1