Edit report at https://bugs.php.net/bug.php?id=71876&edit=1
ID: 71876
Comment by: irasha at yahoo dot com
Reported by: the_djmaze at hotmail dot com
Summary: Memory corruption htmlspecialchars(): charset `*'
not supported
Status: Open
Type: Bug
Package: Strings related
Operating System: Fedora 22
PHP Version: 7.0.8
Block user comment: N
Private report: N
New Comment:
I just ran into this issue on shared hosting account, and wanted to share the workaround solution,
and a potential security concern with this bug.
Shared hosting account (php version 7.0.32), running WordPress blog with a few plugins. error_log
started to fill up 450mb a day with just these errors.
Modifying php.ini was not an option, as there's one for all accounts on that server. Changes to
the code would be overwritten with WP/plugins updates.
The solution that worked was adding "internal_encoding utf-8" to Apache via include config
(has to be done by hosting support rep).
I parsed gigabytes of these lines to see all the "charset" values I got there, and there
were IPs, regexes, some numeric and text values, table names, paths to files from different
accounts(!), etc.. almost all this was from someone else's accounts. I learned of two other
websites that run on the same server just by skimming through these values, and knew the login names
to their accounts from the paths. Makes me wonder how much as a security risk this bug can be on
shared hosting.
Previous Comments:
------------------------------------------------------------------------
[2018-03-13 11:37:05] php_net at dlk dot pl
Temporary workaround is to put charset into function call:
html_entity_decode($x, null, 'utf-8');
https://pastebin.com/d1Z6631j
Also doing ini_set before doesn't work (ini_set/get broken?):
ini_set('default_charset', 'UTF-8');
$y = html_entity_decode($x);
https://pastebin.com/Dp5Aqw0Q
------------------------------------------------------------------------
[2018-03-13 11:21:31] php_net at dlk dot pl
Happens the same with our cakephp project.
Sometimes it even show phpcode in place of charset.
While ini_get('default_charset') returning UTF-8
With whole project error rate is around 50%.
Hard to prepare small test-case because it doesn't return error or showing less frequently when
i remove stuff.
Sometimes also generating HTTP 500:
php-cgi[14874]: segfault at 28d5588 ip 000000000078db23 sp 00007fff98b4e0e8 error 4 in
php-cgi[400000+bdd000]
Examples when it doesn't segfault:
https://pastebin.com/AqkC7p8D
http://proxy.sec3.itdesk.eu/phpbug/bugtest.html
< saved example output
------------------------------------------------------------------------
[2016-07-08 23:39:30] the_djmaze at hotmail dot com
Found more using https://www.google.nl/search?q="Warning:+htmlspecialchars():+charset"+"not+supported"
------------------------------------------------------------------------
[2016-07-08 23:26:50] the_djmaze at hotmail dot com
Tested with PHP 7.0.8 still an issue.
When using
<?php
ini_set('internal_encoding', 'UTF-8');
?>
The issue is completely gone.
------------------------------------------------------------------------
[2016-06-07 13:06:57] the_djmaze at hotmail dot com
Just tested with PHP 7.0.6 and can reproduce it there as well.
When some bigger memory usage occurs (say a CMS page), and then the above script is tested, it shows
the error.
Just using the simple test on a fresh Apache daemon start it didn't show the error.
yohgaki you got me thinking, since PHP runs as a module, it stays loaded in memory.
So you are probably right that the zend_string gets freed because something did a
ini_set('default_charset', 'UTF-8') (or not?!?) in 5.6 and 7?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71876
--
Edit this bug report at https://bugs.php.net/bug.php?id=71876&edit=1