Sec Bug->Bug #77454 [Opn]: mb_scrub() silently truncates after a null byte
| From: | stas@php.net | Date: | Sun, 13 Jan 2019 16:36:15 +0000 |
| Subject: | Sec Bug->Bug #77454 [Opn]: mb_scrub() silently truncates after a null byte | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218922@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77454&edit=1
ID: 77454
Updated by: stas@php.net
Reported by: 64796c6e69 at gmail dot com
Summary: mb_scrub() silently truncates after a null byte
Status: Open
-Type: Security
+Type: Bug
Package: mbstring related
Operating System: any
PHP Version: master-Git-2019-01-13 (Git)
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2019-01-13 16:31:44] 64796c6e69 at gmail dot com
Updating OS.
------------------------------------------------------------------------
[2019-01-13 16:27:15] 64796c6e69 at gmail dot com
Description:
------------
mb_scrub() silently truncates anything after a null byte in a string.
This bug has existed since the function was created.
The arguments are read correctly, but the returned value ignores the length:
https://github.com/php/php-src/blob/30668755b64aa732246d952451f89d1fcfe581f0/ext/mbstring/mbstring.c#L4990
Test script:
---------------
<?php
$str = "before\0after";
var_dump(mb_scrub($str, 'latin1'));
var_dump(mb_scrub($str, 'utf-8'));
var_dump(mb_scrub($str, 'ascii'));
Expected result:
----------------
There should be a null byte in each of these.
string(12) "beforeafter"
string(12) "beforeafter"
string(12) "beforeafter"
Actual result:
--------------
string(6) "before"
string(6) "before"
string(6) "before"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77454&edit=1