Sec Bug->Bug #79715 [Opn]: After the array element reference changes, use array_merge function produc
| From: | stas@php.net | Date: | Fri, 19 Jun 2020 08:02:07 +0000 |
| Subject: | Sec Bug->Bug #79715 [Opn]: After the array element reference changes, use array_merge function produc | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227550@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79715&edit=1
ID: 79715
Updated by: stas@php.net
Reported by: xyzzxf_2013 at 163 dot com
Summary: After the array element reference changes, use
array_merge function produc
Status: Open
-Type: Security
+Type: Bug
Package: Unknown/Other Function
Operating System: centos 7/window 10
PHP Version: 7.3.4nts
Block user comment: N
Private report: Y
Previous Comments:
------------------------------------------------------------------------
[2020-06-19 07:57:15] xyzzxf_2013 at 163 dot com
php version
------------------------------------------------------------------------
[2020-06-19 07:52:16] xyzzxf_2013 at 163 dot com
Description:
------------
Reference value modification of element of array
Test script:
---------------
$a = ['23','25','26'];
foreach ($a as &$v) {
$v = $v+1;
}
function get_check_code($data)
{
foreach ($data as &$a) {
$a = hexdec($a);
}
$sum = dechex(array_sum($data));
return substr($sum, -2);
}
var_dump($a);
$b = get_check_code($a);
$c = array_merge($a,[$b]);
print_r($c);
Expected result:
----------------
var_dump($a) output array(3) { [0] => int(24) [1] => int(26) [2] => int(27) }
print_r($c) output Array ( [0] => 24 [1] => 26 [2] => 39 [3] => 71 )
Actual result:
--------------
The expected result of print_r($c) is Array ( [0] => 24 [1] => 26 [2] => 27 [3] => 71 )
or Array ( [0] => 36 [1] => 38 [2] => 39 [3] => 71 )
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79715&edit=1