Unserialize strings patch
| From: | Robert Macaulay | Date: | Wed, 23 Jun 1999 21:37:19 +0000 |
| Subject: | Unserialize strings patch | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-7480@lists.php.net to get a copy of this message | ||
Unserialize chokes on serialized strings. Serialize encloses strings
with backslashed quotes, while unserialize looks for quotes without
backslashes. Heres the diff. The previous one I sent got base64 encoded.
diff -r -u php3/functions/var.c php3.mod/functions/var.c
--- php3/functions/var.c Fri Jun 18 16:14:02 1999
+++ php3.mod/functions/var.c Fri Jun 18 16:14:35 1999
@@ -304,17 +304,18 @@
return 0;
}
i = atoi(q);
- if (i < 0 || (*p + 3 + i) > max || *((*p) + 1)
!= '\"' ||
- *((*p) + 2 + i) != '\"' || *((*p) + 3 +
i) != ';') {
+
+ if (i < 0 || (*p + 3 + i) > max || *((*p) + 2)
!= '\"' ||
+ *((*p) + 4 + i) != '\"' || *((*p) + 5 +
i) != ';') {
return 0;
}
- (*p) += 2;
+ (*p) += 3;
str = emalloc(i + 1);
if (i > 0) {
memcpy(str, *p, i);
}
str[i] = 0;
- (*p) += i + 2;
+ (*p) += i + 3;
rval->type = IS_STRING;
rval->value.str.val = str;
rval->value.str.len = i;
@@ -335,7 +336,7 @@
while (**p && **p != ':') {
(*p)++;
}
- if (**p != ':' || *((*p) + 1) != '{') {
+ if (**p != ':' && *((*p) + 1) != '{') {
return 0;
}
for ((*p) += 2; **p && **p != '}' && i > 0;
i--)
{