Bug #69217 [Opn]: mb_convert_encoding() passes 0x80 as valid ASCII and ISO-8859-1 code

From: Date: Wed, 14 Apr 2021 13:14:31 +0000
Subject: Bug #69217 [Opn]: mb_convert_encoding() passes 0x80 as valid ASCII and ISO-8859-1 code
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233426@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69217&edit=1

 ID:                 69217
 Updated by:         cmb@php.net
 Reported by:        salsi at icosaedro dot it
 Summary:            mb_convert_encoding() passes 0x80 as valid ASCII and
                     ISO-8859-1 code
 Status:             Open
 Type:               Bug
 Package:            mbstring related
 Operating System:   Slackware 14.1, Windows VISTA
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

> Similar issue:

No, not really.  And I can't reproduce the EFBFBE either.  I'm
getting EFBFBD instead[1], which is the REPLACEMENT CHARACTER, and
that is correct.  Anyhow, if you're still experiencing the
reported behavior, please open a separate ticket.

[1] <https://3v4l.org/XM7Db>


Previous Comments:
------------------------------------------------------------------------
[2020-11-05 18:16:34] denn at vollbio dot de

Similar issue:

mb_convert_encoding("\x81", 'UTF-8', 'cp1252')

returns the bytes 

ef bf be

which is invalid UTF-8: http://www.fileformat.info/info/unicode/char/ffff/index.htm

------------------------------------------------------------------------
[2015-03-11 03:27:16] salsi at icosaedro dot it

Description:
------------
mb_convert_encoding() does not recognize invalid bytes from ill formed ASCII and ISO-8859-1 encoded
binary string. It seems that this 0x80 byte be blindly converted to its corresponding 2-bytes UTF-8
sequence 0xC2 0x80. Instead, converting from UTF-8 in itself the error is detected.

Although not stated anywhere, mb_convert_encoding() should guarantee that either the resulting
output string be perfectly compliant with the requested expected encoding, or it must fail with
error. Returning unexpected results may have safety and security consequences.

Tested on:
- PHP 5.7.0-dev Slackware Linux 14.1
- PHP 5.5.16 Windows VISTA


Test script:
---------------
<?php
error_reporting(PHP_INT_MAX);
ini_set("mbstring.substitute_character", (string) ord("X"));
ini_set("mbstring.strict_detection", "1"); // no effect
// bytes 0x80-0xff are not valid ASCII:
echo 1, rawurlencode(mb_convert_encoding("\x80", "UTF-8", "ASCII")) .
"\n";
// bytes 0x80-0x9f are not valid ISO-8859-1:
echo 2, rawurlencode(mb_convert_encoding("\x80", "UTF-8",
"ISO-8859-1")) . "\n";
echo 3, rawurlencode(mb_convert_encoding("\x80", "UTF-8", "UTF-8")) .
"\n";


Expected result:
----------------
1X
2X
3X


Actual result:
--------------
1%C2%80
2%C2%80
3X



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69217&edit=1


Thread (4 messages)

« previous php.bugs (#233426) next »