#3812 [Opn->Csd]: urlencode not bin-safe

From: Date: Mon, 30 Sep 2002 22:53:55 +0000
Subject: #3812 [Opn->Csd]: urlencode not bin-safe
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-20809@lists.php.net to get a copy of this message
ID: 3812 Updated by: hholzgra@php.net Reported By: baumert@pilot-webdesign.de -Status: Open +Status: Closed Bug Type: Reproducible Crash Operating System: Linux Redhat 5.2, 2.0.36, glibc2 PHP Version: 3.0.15 New Comment: this is ok in php 4.2.3 code Previous Comments: ------------------------------------------------------------------------ [2000-03-12 08:06:24] baumert@pilot-webdesign.de The urlencode function is not binary safe. It retrieves the length of the string to encode as a parameter, then uses strlen to allocate the new buffer. Strlen returns wrong length for the bin-string. After that, the len-parameter is used to fill the buffer => a buffer-overwrite occurs. php 4 beta 4 pl1: change line 241 from str = (unsigned char *) emalloc(3 * strlen(s) + 1); to str = (unsigned char *) emalloc(3 * len + 1); php 3.15 change line 242 from str = (unsigned char *) emalloc(3 * strlen(s) + 1); to str = (unsigned char *) emalloc(3 * len + 1); ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=3812&edit=1

« previous php.bugs (#20809) next »