Bug #71563 [Opn->Fbk]: Buffer Overrun in curl_exec() causing hang

From: Date: Tue, 16 Feb 2016 16:15:40 +0000
Subject: Bug #71563 [Opn->Fbk]: Buffer Overrun in curl_exec() causing hang
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199266@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71563&edit=1

 ID:                 71563
 Updated by:         ab@php.net
 Reported by:        paul at salesintel dot com
 Summary:            Buffer Overrun in curl_exec() causing hang
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            cURL related
 Operating System:   Windows 10 x64
 PHP Version:        7.0.3
 Block user comment: N
 Private report:     N

 New Comment:

Thanks for the report. I'm unable to reproduce the behavior with the snippet you've
posted. Neither with the original, nor when i replace the request string with like $request =
str_repeat('x', 1025);. The script always terminates fast. Is there some other condition i
could possibly have overseen?

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2016-02-09 21:20:46] paul at salesintel dot com

Description:
------------
When a couple of cURL options are set in a specific and valid way, curl_exec() never returns and PHP
does not throw any exception, causing indefinite hang.

Same code in php 5.6.x (in each x32/x64 ts/nts) worked as expected.

In php 7.0.3 (x32/x64 nts, ts not tried) hang occurs.



Test script:
---------------
<?php
repo();
function repo() {
	$location = 'https://mail.microsoft.com/ews/exchange.asmx';
	$request =
"0123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345678901234567890123456789012345!
 6789012345678901234567890123456789012345678901234";

	$ch = curl_init($location);
	curl_setopt($ch, CURLOPT_POSTFIELDS, $request);
	curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC | CURLAUTH_NTLM);
	curl_setopt($ch, CURLOPT_USERPWD, ' ');

	$response = curl_exec($ch);
}

Expected result:
----------------
Call to curl_exec($ch) returns.



Actual result:
--------------
Call to curl_exec($ch) never returns.

However....

If you change $location to an invalid endpoint or one that does not require NTLM, curl_exec()
returns.

If you remove the 'CURLAUTH_BASIC' leaving only 'CURLAUTH_NTLM', curl_exec()
returns;

If you remove 'CURLAUTH_NTLM' leaving only 'CURLAUTH_BASIC', curl_exec()
returns;

If you set an empty string ('') instead of one with one or more characters to
CURLOPT_USERPWD, curl_exec() returns.

$request is a string with 1025 characters. If you remove one character, leaving a (suspiciously
sized) 1024 character length $request, curl_exec($ch) returns.




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71563&edit=1


Thread (3 messages)

« previous php.bugs (#199266) next »