ID: 18792
User updated by: t.bubeck@reinform.de
Reported By: t.bubeck@reinform.de
Status: Critical
Bug Type: HTTP related
Operating System: Red Hat 7.1
PHP Version: 4.2.2
New Comment:
One more thing for clarification: my last checks showed, that the
broken boundary doesn't come from MSIE alone. There must be a proxy (in
my case Netscape Proxy 3.52) between MSIE and PHP. Then you can see
this broken Content-Type entry. I don't know if this only happens with
MSIE and NS Proxy. Maybe with MSIE and other proxies, too?
Using Mozilla 1.0 via Netscape Proxy 3.52 does NOT have the broken
Content-Type.
Both tests were done form the same machine using the identical proxies
and PHP server.
Previous Comments:
------------------------------------------------------------------------
[2002-08-07 15:17:19] rasmus@php.net
Oops, didn't read the entire description. The summary matches a bug
that was fixed. This is actually different.
------------------------------------------------------------------------
[2002-08-07 14:57:50] rasmus@php.net
Critical? Is this not fixed in CVS? I certainly can't reproduce it
here.
------------------------------------------------------------------------
[2002-08-07 14:56:36] sander@php.net
Status -> critical
Can someone with more insight to the POST mechanism in PHP look into
this?
------------------------------------------------------------------------
[2002-08-07 14:50:35] t.bubeck@reinform.de
If you use a HTML form together with multipart/form-data encryption,
then the
browser will send the form data in a POST request surrounded with
boundaries.
Microsoft Internet Explorer (MSIE 5.0 at least) is violating the HTTP
specification (rfc 2616, paragraph 3.7: "Media Types") by repeating
the
content-type in a wrong syntax. This will break PHP in looking for
boundaries
of the multiparts and therefore no global variables will be defined
containing
the form data. This will make it impossible to use PHP together with
MSIE to
process any form data encoded with "multipart/form-data". This results
in many
different bugs reported in large PHP projects (e.g. SquirrelMail) which
are
impossible to fix.
Here is the (broken) HTTP request of MSIE:
POST /squirrel/src/compose.php HTTP/1.0
Via: 1.0 NDCSTR16
Connection: Keep-Alive
Content-Length: 1889
User-Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt)
Content-Type: multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2,multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2,multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2
Host: reinform.hn.org
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/msword, application/vnd.ms-excel,
application/vnd.ms-powerpoint, */*
Accept-Language: de,de,de
Referer:
http://reinform.hn.org/squirrel/src/compose.php,http://reinform.hn.org/squirrel/src/compose.php,http://reinform.hn.org/squirrel/src/compose.php
Pragma: no-cache
Cookie: squirrelmail_language=de_DE; key=AW0RUMJgLK4%3D;
PHPSESSID=0afb8733761a1723a006ce1676d9aa7b
Accept-Encoding: gzip, deflate,gzip, deflate,gzip, deflate
-----------------------------7d29f1d3bad02b2
Content-Disposition: form-data; name="session"
7
-----------------------------7d29f1d3bad02b2
Content-Disposition: form-data; name="send_to"
-----------------------------7d29f1d3bad02b2
The wrong part is the Content-Type which contains more than a single
boundary
statement (which is a rfc2616 violation, because the parameters are
not
seperated by ",").
PHP takes everything after the first '=' as the boundary and will
therefore
look for a boundary
"---------------------------7d29f1d3bad02b2,multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2,multipart/form-data;
boundary=---------------------------7d29f1d3bad02b2" which is never
found in
the data stream. Therefore no parts are found and no variables are
declared.
The following (trivial) patch will fix the bug and is based upong the
current
CVS version of PHP-4.2.2:
diff -r -u php-4.2.2-orig/main/rfc1867.c php-4.2.2/main/rfc1867.c
--- php-4.2.2-orig/main/rfc1867.c Sat Jul 20 21:17:52 2002
+++ php-4.2.2/main/rfc1867.c Wed Aug 7 20:26:28 2002
@@ -599,7 +599,7 @@
SAPI_API SAPI_POST_HANDLER_FUNC(rfc1867_post_handler)
{
- char *boundary, *s=NULL, *start_arr=NULL, *array_index=NULL;
+ char *boundary, *boundary_end, *s=NULL, *start_arr=NULL,
*array_index=NULL;
char *temp_filename=NULL, *lbuf=NULL, *abuf=NULL;
int boundary_len=0, total_bytes=0, cancel_upload=0, is_arr_upload=0,
array_len=0, max_file_size=0;
zval *http_post_files=NULL;
@@ -620,6 +620,10 @@
sapi_module.sapi_error(E_WARNING, "Missing boundary in
multipart/form-data POST data");
return;
}
+ /* search for the end of the boundary */
+ boundary_end = strchr(boundary, ',');
+ if ( boundary_end ) *boundary_end = 0;
+
boundary++;
boundary_len = strlen(boundary);
Would you please apply the patch?
Thanks,
Till
+-------+-------------------------------------------------------------+
| | dr. tilmann bubeck reinform medien- und
|
| rein | informationstechnologie AG
|
| form | cell.: +49 (172) 8 84 29 72 koenigstrasse 80
|
| AG | fax : +49 (711) 7 22 77 34 70173 stuttgart / germany
|
| | email: t.bubeck@reinform.de http://www.reinform.de
|
+-------+-------------------------------------------------------------+
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18792&edit=1