Bug #79481 [Opn->Ver]: data:// wrapper can hidden some characters
| From: | cmb@php.net | Date: | Thu, 16 Apr 2020 07:54:14 +0000 |
| Subject: | Bug #79481 [Opn->Ver]: data:// wrapper can hidden some characters | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226604@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79481&edit=1
ID: 79481
Updated by: cmb@php.net
Reported by: j7ur8 at qq dot com
Summary: data:// wrapper can hidden some characters
-Status: Open
+Status: Verified
Type: Bug
Package: Streams related
Operating System: Windows Linux
PHP Version: 7.4.4
Block user comment: N
Private report: N
New Comment:
> That means we can change it freely, such as
>
data:text/plain;charset=iso-8859-7,%be%fg%be would use the
> iso-8859-7 to handle datas.
No, that is not the case. Unless the base64 flag is set, the data
are just urldecode()d, and any desired/required character encoding
conversion has to be done by the application, which can retrieve
the specified charset from the stream meta data[1].
Given that PHP strings are actually byte arrays, this is pretty
much to be expected, but should be documented nonetheless.
[1] <https://3v4l.org/uGqjf>
Previous Comments:
------------------------------------------------------------------------
[2020-04-16 05:50:42] stas@php.net
Doesn't look like there's any security issue here.
------------------------------------------------------------------------
[2020-04-16 05:47:04] j7ur8 at qq dot com
Description:
------------
From https://www.php.net/manual/en/wrappers.data.php#refsect1-wrappers.data-description`,
i know it refer to RFC 2397. And i found it may not defined securely ?
From RFC 2397
Syntax:
dataurl := "data:" [ mediatype ] [ ";base64" ] "," data
mediatype := [ type "/" subtype ] *( ";" parameter )
data := *urlchar
parameter := attribute "=" value
and if <mediatype> is omitted, it defaults to text/plain;charset=US-ASCII. That
means we can change it freely, such as data:text/plain;charset=iso-8859-7,%be%fg%be
would use the iso-8859-7 to handle datas. But i do not think php supports it wholly which results
to characters can hide in the data wrapper stream.
Test script:
---------------
<?php
echo file_get_contents('data:,cc')."\n"; # valid
echo file_get_contents('data://asdc/asd;ccc=ccc,cc')."\n"; # with bad characters
hide in
Expected result:
----------------
cc
cc
Actual result:
--------------
cc
cc
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79481&edit=1