|
|
| |
| PHP 5.4SVN-2012-02-03 htmlspecialchars/entities suffers from buffer overflow vulnerability |
| |
Credit:
The information has been provided by cataphract.
|
| |
Vulnerable Systems:
* PHP 5.4SVN-2012-02-03
Description:
------------
Long entities can cause a buffer overflow because the loop only guarantees 40 bytes available in beginning.
Test script:
---------------
<?php
echo
htmlspecialchars('"""""""""""""""""""""""""""""""""""""""""""""',
ENT_QUOTES, 'UTF-8', false), "\n";
Disclosure Timeline:
Published: 2012-02-03
|
|
blog comments powered by
|