Bug #43225 [ReO->Dup]: fputcsv incorrectly handles cells ending in \ followed by "
| From: | cmb@php.net | Date: | Thu, 13 Sep 2018 12:35:47 +0000 |
| Subject: | Bug #43225 [ReO->Dup]: fputcsv incorrectly handles cells ending in \ followed by " | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217027@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=43225&edit=1
ID: 43225
Updated by: cmb@php.net
Reported by: ed at bronto dot com
Summary: fputcsv incorrectly handles cells ending in \
followed by "
-Status: Re-Opened
+Status: Duplicate
Type: Bug
Package: Filesystem function related
Operating System: Centos
PHP Version: 5.2.4
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Well, this behavior is there for so many years, that we can't
change it easily for BC reasons (and frankly, the sense of *this*
escaping escapes me). Therefore I'm closing this ticket as
duplicate of request #38301 and request #51496, respectively.
Previous Comments:
------------------------------------------------------------------------
[2018-02-15 13:22:57] cmb@php.net
Related To: Bug #75418
------------------------------------------------------------------------
[2017-09-11 23:53:06] cmb@php.net
> Still not fixed after almost 10 years?
It is not as simple. We first have to understand why fputcsv() and
friends support an escape character, which is an unrecognized
concept for RFC 4180; however, this RFC is informal and never made
it to a standard, so an escape character may make perfect sense.
But how exactly is it supposed to work?
Anyhow, "disabling" the escape character as plentysu already said,
is suffienct to get the desired result, see
<https://3v4l.org/eW2Mt>. This should be possible in a
more
intuitive way, though, see request #51496.
------------------------------------------------------------------------
[2017-04-25 09:38:24] enumag at gmail dot com
Still not fixed after almost 10 years? The thing is this can result in formula injection.
http://blog.securelayer7.net/how-to-perform-csv-excel-macro-injection/
For example I have this string (it should go into one cell):
=,test'\","",=cmd|' /C calc'!A0"
According to the article I sanitize it by escaping the = at the beginning with an apostrphe.
'=,test'\","",=cmd|' /C calc'!A0"
Because of this bug however this string can still cause an injection because this bug causes the
string to split into multiple cells and the second = is not escped.
------------------------------------------------------------------------
[2015-09-16 04:33:26] plentysu at kkbox dot com
One thinking to
disable escape method: fputcsv($handle, $array, ',',
'"', "\0")
------------------------------------------------------------------------
[2015-07-25 22:14:45] marc at ermshaus dot org
The issues with PHPâs CSV functions also seem to be exploitable.
<?php
$handle = fopen('php://memory', 'w+b');
fputcsv($handle, [
'foo bar\\', # 1
'baz quz', # 2
'x', # 3
'y', # 4
'z', # 5
'foo\\\\",bar' # 6
]);
rewind($handle);
var_dump(fgetcsv($handle));
// array(6) {
// [0]=> string(18) "foo bar\",baz quz"" # 1
// [1]=> string(1) "x" # 2 (was # 3)
// [2]=> string(1) "y" # 3 (was # 4)
// [3]=> string(1) "z" # 4 (was # 5)
// [4]=> string(5) "foo\\" # 5
// [5]=> string(4) "bar"" # 6
// }
3v4l.org: http://3v4l.org/LTnC1
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=43225
--
Edit this bug report at https://bugs.php.net/bug.php?id=43225&edit=1