Unserialize strings patch

From: Date: Wed, 23 Jun 1999 21:37:19 +0000
Subject: Unserialize strings patch
Groups: php.dev 
Request: Send a blank email to php-dev+get-7480@lists.php.net to get a copy of this message
Unserialize chokes on serialized strings. Serialize encloses strings with backslashed quotes, while unserialize looks for quotes without backslashes. Heres the diff. The previous one I sent got base64 encoded. diff -r -u php3/functions/var.c php3.mod/functions/var.c --- php3/functions/var.c Fri Jun 18 16:14:02 1999 +++ php3.mod/functions/var.c Fri Jun 18 16:14:35 1999 @@ -304,17 +304,18 @@ return 0; } i = atoi(q); - if (i < 0 || (*p + 3 + i) > max || *((*p) + 1) != '\"' || - *((*p) + 2 + i) != '\"' || *((*p) + 3 + i) != ';') { + + if (i < 0 || (*p + 3 + i) > max || *((*p) + 2) != '\"' || + *((*p) + 4 + i) != '\"' || *((*p) + 5 + i) != ';') { return 0; } - (*p) += 2; + (*p) += 3; str = emalloc(i + 1); if (i > 0) { memcpy(str, *p, i); } str[i] = 0; - (*p) += i + 2; + (*p) += i + 3; rval->type = IS_STRING; rval->value.str.val = str; rval->value.str.len = i; @@ -335,7 +336,7 @@ while (**p && **p != ':') { (*p)++; } - if (**p != ':' || *((*p) + 1) != '{') { + if (**p != ':' && *((*p) + 1) != '{') { return 0; } for ((*p) += 2; **p && **p != '}' && i > 0; i--) {

« previous php.dev (#7480) next »