1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 |
From: cataphract Operating system: Any PHP version:5.4SVN-2012-02-03 (SVN) Package:Reproducible crash Bug Type: Bug Bug description:Buffer overflow on htmlspecialchars/entities with $double=false Description: ------------ Long entities can cause a buffer overflow because the loop only guarantees 40 bytes available in beginning. Test script: --------------- <?php echo htmlspecialchars('"""""""""""""""""""""""""""""""""""""""""""""', ENT_QUOTES, 'UTF-8', false), "\n"; |