#47797 [NEW]: Security vulnerability in preg_replace is not documented clearly enough

From: Date: Thu, 26 Mar 2009 23:38:17 +0000
Subject: #47797 [NEW]: Security vulnerability in preg_replace is not documented clearly enough
Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-2052@lists.php.net to get a copy of this message
From: spam04 at pornel dot net Operating system: * PHP version: Irrelevant PHP Bug Type: Documentation problem Bug description: Security vulnerability in preg_replace is not documented clearly enough Description: ------------ Re bug #47796: Documentation for preg_replace only suggests to check PHP's string syntax in non-alarming way. Given that replacement code with double quotes (which is even used in manual itself) could enable remote code execution, there should be a clearly worded and highlighted warning about this. The fragment "This is done to ensure that no syntax errors arise from backreference usage with either single or double quotes" could lead readers to believe that PHP escapes strings thoroughly and properly. That is not the case: preg_replace('/.*/e','"$0"', '{$foo[}'); Expected result: ---------------- Huge red box in manual with "Don't use /e". -- Edit bug report at http://bugs.php.net/?id=47797&edit=1 -- Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=47797&r=trysnapshot52 Try a CVS snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=47797&r=trysnapshot53 Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=47797&r=trysnapshot60 Fixed in CVS: http://bugs.php.net/fix.php?id=47797&r=fixedcvs Fixed in CVS and need be documented: http://bugs.php.net/fix.php?id=47797&r=needdocs Fixed in release: http://bugs.php.net/fix.php?id=47797&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=47797&r=needtrace Need Reproduce Script: http://bugs.php.net/fix.php?id=47797&r=needscript Try newer version: http://bugs.php.net/fix.php?id=47797&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=47797&r=support Expected behavior: http://bugs.php.net/fix.php?id=47797&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=47797&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=47797&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=47797&r=globals PHP 4 support discontinued: http://bugs.php.net/fix.php?id=47797&r=php4 Daylight Savings: http://bugs.php.net/fix.php?id=47797&r=dst IIS Stability: http://bugs.php.net/fix.php?id=47797&r=isapi Install GNU Sed: http://bugs.php.net/fix.php?id=47797&r=gnused Floating point limitations: http://bugs.php.net/fix.php?id=47797&r=float No Zend Extensions: http://bugs.php.net/fix.php?id=47797&r=nozend MySQL Configuration Error: http://bugs.php.net/fix.php?id=47797&r=mysqlcfg

« previous php.doc.bugs (#2052) next »