Bug #43225 [ReO->Dup]: fputcsv incorrectly handles cells ending in \ followed by "

From: Date: Thu, 13 Sep 2018 12:35:47 +0000
Subject: Bug #43225 [ReO->Dup]: fputcsv incorrectly handles cells ending in \ followed by "
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217027@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=43225&edit=1 ID: 43225 Updated by: cmb@php.net Reported by: ed at bronto dot com Summary: fputcsv incorrectly handles cells ending in \ followed by " -Status: Re-Opened +Status: Duplicate Type: Bug Package: Filesystem function related Operating System: Centos PHP Version: 5.2.4 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Well, this behavior is there for so many years, that we can't change it easily for BC reasons (and frankly, the sense of *this* escaping escapes me). Therefore I'm closing this ticket as duplicate of request #38301 and request #51496, respectively. Previous Comments: ------------------------------------------------------------------------ [2018-02-15 13:22:57] cmb@php.net Related To: Bug #75418 ------------------------------------------------------------------------ [2017-09-11 23:53:06] cmb@php.net > Still not fixed after almost 10 years? It is not as simple. We first have to understand why fputcsv() and friends support an escape character, which is an unrecognized concept for RFC 4180; however, this RFC is informal and never made it to a standard, so an escape character may make perfect sense. But how exactly is it supposed to work? Anyhow, "disabling" the escape character as plentysu already said, is suffienct to get the desired result, see <https://3v4l.org/eW2Mt>. This should be possible in a more intuitive way, though, see request #51496. ------------------------------------------------------------------------ [2017-04-25 09:38:24] enumag at gmail dot com Still not fixed after almost 10 years? The thing is this can result in formula injection. http://blog.securelayer7.net/how-to-perform-csv-excel-macro-injection/ For example I have this string (it should go into one cell): =,test'\","",=cmd|' /C calc'!A0" According to the article I sanitize it by escaping the = at the beginning with an apostrphe. '=,test'\","",=cmd|' /C calc'!A0" Because of this bug however this string can still cause an injection because this bug causes the string to split into multiple cells and the second = is not escped. ------------------------------------------------------------------------ [2015-09-16 04:33:26] plentysu at kkbox dot com One thinking to disable escape method: fputcsv($handle, $array, ',', '"', "\0") ------------------------------------------------------------------------ [2015-07-25 22:14:45] marc at ermshaus dot org The issues with PHP’s CSV functions also seem to be exploitable. <?php $handle = fopen('php://memory', 'w+b'); fputcsv($handle, [ 'foo bar\\', # 1 'baz quz', # 2 'x', # 3 'y', # 4 'z', # 5 'foo\\\\",bar' # 6 ]); rewind($handle); var_dump(fgetcsv($handle)); // array(6) { // [0]=> string(18) "foo bar\",baz quz"" # 1 // [1]=> string(1) "x" # 2 (was # 3) // [2]=> string(1) "y" # 3 (was # 4) // [3]=> string(1) "z" # 4 (was # 5) // [4]=> string(5) "foo\\" # 5 // [5]=> string(4) "bar"" # 6 // } 3v4l.org: http://3v4l.org/LTnC1 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=43225 -- Edit this bug report at https://bugs.php.net/bug.php?id=43225&edit=1

« previous php.bugs (#217027) next »