summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMichael Wallner <mike@php.net>2014-09-09 06:54:23 +0200
committerMichael Wallner <mike@php.net>2014-09-09 06:54:23 +0200
commit8d1099ac0574f3a42036085641c2df03a1d5f731 (patch)
tree93db4982d906a9479f815a27219aaee6109a99e8
parent4bdd9aabdd9ddabac9fe253aab4c8366691c5171 (diff)
downloadphp-git-8d1099ac0574f3a42036085641c2df03a1d5f731.tar.gz
duplicate value's string for the SAPI filter
reported by sesser; tyrael, do you take care of the bug/NEWS?
-rw-r--r--main/php_variables.c12
1 files changed, 7 insertions, 5 deletions
diff --git a/main/php_variables.c b/main/php_variables.c
index 90cfcb20bc..b2df88be61 100644
--- a/main/php_variables.c
+++ b/main/php_variables.c
@@ -241,7 +241,7 @@ typedef struct post_var_data {
static zend_bool add_post_var(zval *arr, post_var_data_t *var, zend_bool eof TSRMLS_DC)
{
- char *ksep, *vsep;
+ char *ksep, *vsep, *val;
size_t klen, vlen;
/* FIXME: string-size_t */
unsigned int new_vlen;
@@ -272,15 +272,17 @@ static zend_bool add_post_var(zval *arr, post_var_data_t *var, zend_bool eof TSR
vlen = 0;
}
-
php_url_decode(var->ptr, klen);
+
+ val = estrndup(ksep, vlen);
if (vlen) {
- vlen = php_url_decode(ksep, vlen);
+ vlen = php_url_decode(val, vlen);
}
- if (sapi_module.input_filter(PARSE_POST, var->ptr, &ksep, vlen, &new_vlen TSRMLS_CC)) {
- php_register_variable_safe(var->ptr, ksep, new_vlen, arr TSRMLS_CC);
+ if (sapi_module.input_filter(PARSE_POST, var->ptr, &val, vlen, &new_vlen TSRMLS_CC)) {
+ php_register_variable_safe(var->ptr, val, new_vlen, arr TSRMLS_CC);
}
+ efree(val);
var->ptr = vsep + (vsep != var->end);
return 1;