Bug #78929 [NEW]: Cookie value parsing. Valid character changed into invalid. RFC6265 RFC2616
| From: | kachalin dot alexey at gmail dot com | Date: | Sun, 08 Dec 2019 18:25:16 +0000 |
| Subject: | Bug #78929 [NEW]: Cookie value parsing. Valid character changed into invalid. RFC6265 RFC2616 | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-224130@lists.php.net to get a copy of this message | ||
From: kachalin dot alexey at gmail dot com
Operating system: Irrelevant
PHP version: Irrelevant
Package: URL related
Bug Type: Bug
Bug description:Cookie value parsing. Valid character changed into invalid. RFC6265 RFC2616
Description:
------------
While cookie parsing PHP violate RFC standards and change valid
character + "plus" x2B into invalid character space x20
How to check
1. Set cookie by php function setrawcookie(***)
2. Make sure it set correctly in browser
3. Make request with cookie and check that $_COOKIE[ COOKIE_NAME ] have
cookie which plus sign was changed into space.
Valid characters for value defined in RFC6265.4.1.1
Valid characters for name(token) defined in RFC6265.4.1.1. ->
RFC2616.2.2
http://www.faqs.org/rfcs/rfc6265.html
http://www.faqs.org/rfcs/rfc2616.html
This applicable only for a value, because PHP documentation put
restriction to use letters and numbers only for a cookie name.
I haven't found any restriction on value and believe value should use
character defined by RFC.
Test script:
---------------
<?php
/* Run twice
* At first time to set the cookie.
* At second time to validate the cookie value and check an error
message.
*/
$cookieName = 'RFC6265';
$cookieValue =
'#$%&\'()*+-./0123456789<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[]^_`abcdefghijklmnopqrstuvwxyz{|}~!';
if(empty($_COOKIE[ $cookieName ]))// Set cookie for first time.
{
setrawcookie($cookieName, $cookieValue);
}
else// Compare received cookie value with set value. Should be same.
Echo on error.
{
for($i = strlen($cookieValue)-1; $i > -1; --$i)
{
if(!isset($_COOKIE[ $cookieName ][ $i ]))
{echo "\n<br>Cookie value symbol is lost:". $cookieValue[ $i
];}
elseif($cookieValue[ $i ] != $_COOKIE[ $cookieName ][ $i ] )
{echo "\n<br>Cookie value symbol is different:".$cookieValue[ $i
];}
}
}
Expected result:
----------------
Empty output. No error message on success execution.
Actual result:
--------------
If error happened message will showed with wrong or lost characters.
--
Edit bug report at https://bugs.php.net/bug.php?id=78929&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78929&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78929&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78929&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78929&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78929&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78929&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78929&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78929&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78929&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78929&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78929&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78929&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78929&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78929&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78929&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78929&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78929&r=mysqlcfg