From ea46f79a97f2e92306573fcb3a17df90756cb5c9 Mon Sep 17 00:00:00 2001 From: Stanislav Malyshev Date: Wed, 3 Jan 2001 10:52:26 +0000 Subject: [PATCH] Fix #8486 (name= without quotes in MIME Content-Disposition header) Ported fix by kk/sas from PHP 3 --- main/rfc1867.c | 15 ++++++++++++--- 1 file changed, 12 insertions(+), 3 deletions(-) diff --git a/main/rfc1867.c b/main/rfc1867.c index 40567f3507..195b567f80 100644 --- a/main/rfc1867.c +++ b/main/rfc1867.c @@ -167,11 +167,20 @@ static void php_mime_split(char *buf, int cnt, char *boundary, zval *array_ptr S SAFE_RETURN; } loc = memchr(ptr, '\n', rem); - name = strstr(ptr, " name=\""); + name = strstr(ptr, " name="); if (name && name < loc) { - name += 7; + name += 6; s = memchr(name, '\"', loc - name); - if (!s) { + if ( name == s ) { + name++; + s = memchr(name, '\"', loc - name); + if(!s) { + php_error(E_WARNING, "File Upload Mime headers garbled name: [%c%c%c%c%c]", *name, *(name + 1), *(name + 2), *(name + 3), *(name + 4)); + SAFE_RETURN; + } + } else if(!s) { + s = loc; + } else { php_error(E_WARNING, "File Upload Mime headers garbled name: [%c%c%c%c%c]", *name, *(name + 1), *(name + 2), *(name + 3), *(name + 4)); SAFE_RETURN; } -- 2.50.1