Re: cvs: php4 /ext/standard string.c

From: Date: Wed, 22 Aug 2001 04:00:23 +0000
Subject: Re: cvs: php4 /ext/standard string.c
References: 1  Groups: php.cvs 
Request: Send a blank email to php-cvs+get-7005@lists.php.net to get a copy of this message
Are you sure that when you do p+2 and p+3 that you are definitely not passing the end of the string? I don't have time to go over the code now but it looks dangerous. Andi At 02:03 AM 8/22/2001 +0000, Gavin Sherry wrote:
swm             Tue Aug 21 22:03:15 2001 EDT
Modified files:
    /php4/ext/standard  string.c
Log: Changed php_strip_tags() to check if <? was XML code. Index: php4/ext/standard/string.c diff -u php4/ext/standard/string.c:1.225 php4/ext/standard/string.c:1.226
--- php4/ext/standard/string.c:1.225    Tue Aug 21 08:57:52 2001
+++ php4/ext/standard/string.c Tue Aug 21 22:03:14 2001 @@ -18,7 +18,7 @@
    +----------------------------------------------------------------------+
*/ -/* $Id: string.c,v 1.225 2001/08/21 12:57:52 zeev Exp $ */ +/* $Id: string.c,v 1.226 2001/08/22 02:03:14 swm Exp $ */ /* Synced with php 3.0 revision 1.193 1999-06-16 [ssb] */ @@ -3190,6 +3190,9 @@
        When an allow string is passed in we keep track of the string
        in state 1 and when the tag is closed check it against the
        allow string to see if we should allow it.
+
+       swm: Added ability to strip <?xml tags without assuming it PHP
+       code.
*/ PHPAPI void php_strip_tags(char *rbuf, int len, int state, char *allow, int allow_len) { @@ -3286,13 +3289,18 @@
                                break;
                        case '?':
-                               if (state==1 && *(p-1)=='<') {
+                               if (state==1 && *(p-1)=='<' && *(p+1) != 'x'
+                                 && *(p+2) != 'm' && *(p+3) != 'l') {
+
                                        br=0;
                                        state=2;
                                        break;
                                }
-                               /* fall-through */
+                                       /* else, it is xml, since state == 1, lets just fall through
+                                       * to '>'
+                                       */
+                               /* fall-through */
                        default:
                                if (state == 0) {
                                        *(rp++) = c;
@@ -3301,7 +3309,7 @@
                                        if( (tp-tbuf)>=PHP_TAG_BUF_SIZE ) { /* no buffer overflows */
                                                tp = tbuf;
                                        }
-                               }
+                               }
                                break;
                }
                c = *(++p);
-- PHP CVS Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-cvs-unsubscribe@lists.php.net For additional commands, e-mail: php-cvs-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net


« previous php.cvs (#7005) next »