#47797 [NEW]: Security vulnerability in preg_replace is not documented clearly enough
| From: | spam04 at pornel dot net | Date: | Thu, 26 Mar 2009 23:38:17 +0000 |
| Subject: | #47797 [NEW]: Security vulnerability in preg_replace is not documented clearly enough | ||
| Groups: | php.doc.bugs | ||
| Request: | Send a blank email to doc-bugs+get-2052@lists.php.net to get a copy of this message | ||
From: spam04 at pornel dot net
Operating system: *
PHP version: Irrelevant
PHP Bug Type: Documentation problem
Bug description: Security vulnerability in preg_replace is not documented clearly enough
Description:
------------
Re bug #47796:
Documentation for preg_replace only suggests to check PHP's string
syntax in non-alarming way.
Given that replacement code with double quotes (which is even used in
manual itself) could enable remote code execution, there should be a
clearly worded and highlighted warning about this.
The fragment "This is done to ensure that no syntax errors arise from
backreference usage with either single or double quotes" could lead
readers to believe that PHP escapes strings thoroughly and properly.
That is not the case:
preg_replace('/.*/e','"$0"', '{$foo[}');
Expected result:
----------------
Huge red box in manual with "Don't use /e".
--
Edit bug report at http://bugs.php.net/?id=47797&edit=1
--
Try a CVS snapshot (PHP 5.2): http://bugs.php.net/fix.php?id=47797&r=trysnapshot52
Try a CVS snapshot (PHP 5.3): http://bugs.php.net/fix.php?id=47797&r=trysnapshot53
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=47797&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=47797&r=fixedcvs
Fixed in CVS and need be documented: http://bugs.php.net/fix.php?id=47797&r=needdocs
Fixed in release: http://bugs.php.net/fix.php?id=47797&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=47797&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=47797&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=47797&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=47797&r=support
Expected behavior: http://bugs.php.net/fix.php?id=47797&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=47797&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=47797&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=47797&r=globals
PHP 4 support discontinued: http://bugs.php.net/fix.php?id=47797&r=php4
Daylight Savings: http://bugs.php.net/fix.php?id=47797&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=47797&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=47797&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=47797&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=47797&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=47797&r=mysqlcfg