Bug #80559 [Com]: xmlrpc_encode creates bad xml entities for chars 200 to 209
| From: | giunta dot gaetano at gmail dot com | Date: | Tue, 29 Dec 2020 10:16:51 +0000 |
| Subject: | Bug #80559 [Com]: xmlrpc_encode creates bad xml entities for chars 200 to 209 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-231295@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80559&edit=1
ID: 80559
Comment by: giunta dot gaetano at gmail dot com
Reported by: giunta dot gaetano at gmail dot com
Summary: xmlrpc_encode creates bad xml entities for chars 200
to 209
Status: Not a bug
Type: Bug
Package: XMLRPC-EPI related
Operating System: ubuntu
PHP Version: 7.4.13
Block user comment: N
Private report: N
New Comment:
Indeed I experienced this bug on Ubuntu's native php version, which uses a shared library for
libxmlrpc-epi.
The problem has been reported upstream to Debian, and has been lingering in their bug tracker for a
while :-( see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883747
Also, I managed to dig out the original bug report which led to this issue being fixed within
php's source code: https://bugs.php.net/bug.php?id=28597
I know that the xmlrpc extension has been removed from php 8 and is thus probably in a strict
'maintenance only' mode, but would it make sense to try to make it easier for end users to
install the non-buggy version from PECL?
Previous Comments:
------------------------------------------------------------------------
[2020-12-28 22:25:33] requinix@php.net
*does not work (note the if c >= 10)
------------------------------------------------------------------------
[2020-12-28 22:25:03] requinix@php.net
Upstream bug.
Bundled libxmlrpc-epi is good
http://git.php.net/?p=pecl/networking/xmlrpc.git;a=blob;f=libxmlrpc/xml_element.c;h=16787593516d492fcf720b0d3eea22934bae02f0;hb=refs/heads/master#l279
but this version on SourceForge does
https://sourceforge.net/p/xmlrpc-epi/git/ci/master/tree/src/xml_element.c#l290
------------------------------------------------------------------------
[2020-12-28 20:17:43] giunta dot gaetano at gmail dot com
Description:
------------
Function xmlrpc_encode and xmlrpc_encode_request do encode all characters above 127 to their numeric
entity representation, eg: chr(129) => ''
However there seems to be a bug for characters between 200 and 209 - for those the numeric entities
generated are '' to ''.
The code in the source library, file 'xml_element.c' seems to have a bug in function
create_xml_escape. The same bug would apply for characters 100 to 109, however that does not happen
because those characters are not encoded as entities in the first place.
Test script:
---------------
echo xmlrpc_encode(chr(199).chr(200).chr(209).chr(210);
Expected result:
----------------
<?xml version="1.0"
encoding="utf-8"?><params><param><value><string>ÇÈÑÒ</string></value></param></params>
Actual result:
--------------
<?xml version="1.0"
encoding="utf-8"?><params><param><value><string>ÇÒ</string></value></param></params>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80559&edit=1