Re: Bug #757 Updated: strpos is not binary save

From: Date: Fri, 18 Sep 1998 15:14:06 +0000
Subject: Re: Bug #757 Updated: strpos is not binary save
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-1237@lists.php.net to get a copy of this message
On Fri, 18 Sep 1998, Rasmus Lerdorf wrote: > > strpos() as it is right now is not binary safe, and > > that check is intentional, to protect the binary > > unsafe implementation from receiving unexpected > > arguments (and thus crash). > > That's not much of a check though. If the needle argument can crash it, > then so can the haystack argument which is not checked. What we really > need is a memstr() function. The strchr() should probably be changed to > memchr(). The check is quite alright actually. The haystack argument can't crash strstr() since it may be empty by definition, whereas the delimiter argument must not be. If there's binary data in the haystack argument, then anything past the first NULL would simply be silently ignored. The function as it was is in working condition, binary unsafe, but safe from crashes. Coding memstr() would make it binary safe, but I'm not sure how necessary it is... Zeev -- ----------------------------------------------------- Zeev Suraski <zeev@php.net> For a PGP public key, finger bourbon@netvision.net.il -- PHP Development Mailing List http://www.php.net/ To unsubscribe send an empty message to php-dev-unsubscribe@lists.php.net For help: php-dev-help@lists.php.net

« previous php.dev (#1237) next »