Bug #75236 [Ver->Csd]: infinite loop when printing an error-message

From: Date: Wed, 20 Sep 2017 23:06:38 +0000
Subject: Bug #75236 [Ver->Csd]: infinite loop when printing an error-message
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211284@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75236&edit=1 ID: 75236 Updated by: ajf@php.net Reported by: lzsiga at freemail dot c3 dot hu Summary: infinite loop when printing an error-message -Status: Verified +Status: Closed Type: Bug Package: Reproducible crash Operating System: AIX, Linux PHP Version: 7.1.9 Assigned To: ajf Block user comment: N Private report: N New Comment: Automatic comment on behalf of ajf@ajf.me Revision: http://git.php.net/?p=php-src.git;a=commit;h=418f97443aa44644bdf81b96fb726518754724f5 Log: Fix bug #75236 Previous Comments: ------------------------------------------------------------------------ [2017-09-20 22:18:48] ajf@php.net Argh, I'm sorry about this, I probably should have tested that fix more than I did. I'm looking into this now. ------------------------------------------------------------------------ [2017-09-20 22:00:39] cmb@php.net > instead of 'htmlentities' 'htmlspecialchars' should be called That can cause issues if the string is encoded differently than what the output expects. > htmlspecialchars only deals with ASCII characters like < > & ' " Applying htmlspecialchars() on an arbitrary encoding assuming it would be ASCII compatible causes issues. Consider an UTF-16 encoded ļ (U+0131). Anyhow, the behavioral change introduced by fixing bug #74725 appears to be a severe bug, since htmlspecialchars() segfaults due to infinite recursion for any unsupported default_charset, if html_errors is enabled: <?php ini_set('html_errors', true); ini_set('default_charset', 'ISO-8859-2'); htmlentities('foo', ENT_COMPAT, 'ISO-8859-2'); A possible solution might be to temporarily change the default_charset to UTF-8 while calling php_error_docref()[1], and to remove charset_hint from the message, to ensure that we're really dealing with UTF-8 (actually, ASCII) here. Andrea, could you please have a look at this issue? [1] <https://github.com/php/php-src/blob/php-7.1.9/ext/standard/html.c#L463-L464> ------------------------------------------------------------------------ [2017-09-20 20:23:30] lzsiga at freemail dot c3 dot hu Well, yes, my fault; what I should have suggested is that instead of 'htmlentities' 'htmlspecialchars' should be called, with hardcoded 'charset='ISO-8859-1' (or 'ASCII' if there is such an option -- htmlspecialchars only deals with ASCII characters like < > & ' " ) ------------------------------------------------------------------------ [2017-09-20 17:01:12] cmb@php.net I can confirm this issue. It happens for all unsupported "charsets", i.e. for those that htmlentities() would throw a respective warning. See <https://github.com/php/php-src/blob/php-7.1.9/ext/standard/html.c#L448-L467>. > The problem could be solved if htmlentities didn't verify UTF8-validity and > silently ignored 'charset' parameter. That would cause other issues, though. ------------------------------------------------------------------------ [2017-09-20 16:27:38] lzsiga at freemail dot c3 dot hu Description: ------------ Printing an error message with settings 'html_errors=true' and 'default_charset=ISO-8859-2' leads to infinite loop. Components of the loop: determine_charset -> php_error_docref0 -> php_verror -> php_escape_html_entities -> php_escape_html_entities_ex -> determine_charset This bug was introduced in version 7.1.9, main/main.c line 765 before: replace_buffer = php_escape_html_entities((unsigned char*)buffer, buffer_len, 0, ENT_COMPAT, NULL); after: php_escape_html_entities((unsigned char*)buffer, buffer_len, 0, ENT_COMPAT, SG(default_charset)); (A note: The problem could be solved if htmlentities didn't verify UTF8-validity and silently ignored 'charset' parameter. See also: https://bugs.php.net/bug.php?id=47494 ) Test script: --------------- #!/usr/local/bin/php <?php ini_set('html_errors', true); ini_set('default_charset', 'ISO-8859-2'); printf ("before getfilecontent\n"); file_get_contents ('no/suchfile'); printf ("after getfilecontent\n"); ?> Expected result: ---------------- before getfilecontent PHP Warning: file_get_contents(no/suchfile): failed to open stream: No such file or directory in /local/home/projects/devel/phptest/loopy.php on line 8 <br /> <b>Warning</b>: file_get_contents(no/suchfile): failed to open stream: No such file or directory in <b>/local/home/projects/devel/phptest/loopy.php</b> on line <b>8</b><br /> after getfilecontent Actual result: -------------- before getfilecontent Segmentation fault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75236&edit=1

« previous php.bugs (#211284) next »