Bug #77327 [NEW]: '0' == true, if on the right and stored as variable

From: Date: Thu, 20 Dec 2018 18:29:44 +0000
Subject: Bug #77327 [NEW]: '0' == true, if on the right and stored as variable
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218533@lists.php.net to get a copy of this message
From: pegasus at vaultwiki dot org Operating system: Centos 7 PHP version: 7.2Git-2018-12-20 (Git) Package: *General Issues Bug Type: Bug Bug description:'0' == true, if on the right and stored as variable Description: ------------ I recently noticed a behavior change in an application running on my web site where configuration values in the application that were disabled were being treated like they were still enabled. The application stores disabled values as '0' strings and relies on PHP's implicit conversion (bool)'0' to false. I have reduced the test cases and it seems to be related to whether there is a truthy value to the left of the '0' in an AND expression, and the evaluation is being stored in a variable. Depending on the way an application uses such an expression, this can have far-reaching implications for security and the integrity of the application data. Discovered on 7.2.11 (although I noticed the behavior for quite some versions before that), and confirmed still occurring on Git branch 7.2 as of 12/20/18. Test script: --------------- // basic tests var_dump(true AND '0'); // correctly returns false $test = true AND '0'; var_dump($test); // returns true, should be false -- Edit bug report at https://bugs.php.net/bug.php?id=77327&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77327&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77327&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77327&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=77327&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=77327&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=77327&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=77327&r=needscript Try newer version: https://bugs.php.net/fix.php?id=77327&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=77327&r=support Expected behavior: https://bugs.php.net/fix.php?id=77327&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=77327&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=77327&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=77327&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77327&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=77327&r=dst IIS Stability: https://bugs.php.net/fix.php?id=77327&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=77327&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=77327&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=77327&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=77327&r=mysqlcfg

« previous php.bugs (#218533) next »