#47797 [Opn->Bgs]: Security vulnerability in preg_replace is not documented clearly enough

From: Date: Tue, 21 Apr 2009 03:06:54 +0000
Subject: #47797 [Opn->Bgs]: Security vulnerability in preg_replace is not documented clearly enough
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-2125@lists.php.net to get a copy of this message
 ID:               47797
 Updated by:       fa@php.net
 Reported By:      spam04 at pornel dot net
-Status:           Open
+Status:           Bogus
 Bug Type:         Documentation problem
 Operating System: *
 PHP Version:      Irrelevant
 New Comment:

Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php




Previous Comments:
------------------------------------------------------------------------

[2009-03-26 23:38:17] spam04 at pornel dot net

Description:
------------
Re bug #47796:

Documentation for preg_replace only suggests to check PHP's string 
syntax in non-alarming way.
 
Given that replacement code with double quotes (which is even used in 
manual itself) could enable remote code execution, there should be a 
clearly worded and highlighted warning about this.

The fragment "This is done to ensure that no syntax errors arise from 
backreference usage with either single or double quotes" could lead 
readers to believe that PHP escapes strings thoroughly and properly.
That is not the case:

preg_replace('/.*/e','"$0"', '{$foo[}');


Expected result:
----------------
Huge red box in manual with "Don't use /e".




------------------------------------------------------------------------


-- 
Edit this bug report at http://bugs.php.net/?id=47797&edit=1



Thread (2 messages)

« previous php.doc.bugs (#2125) next »