Bug #71861 [Opn]: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang
| From: | laruence@php.net | Date: | Sun, 20 Mar 2016 12:41:26 +0000 |
| Subject: | Bug #71861 [Opn]: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199958@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71861&edit=1
ID: 71861
Updated by: laruence@php.net
Reported by: paul at salesintel dot com
Summary: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec()
causing hang
Status: Open
Type: Bug
Package: cURL related
Operating System: Windows 10 x64
PHP Version: 7.0.4
Block user comment: N
Private report: N
New Comment:
Seems like a curl bug?
==95176== Conditional jump or move depends on uninitialised value(s)
==95176== at 0x79128CD: gnutls_session_get_data (in
/usr/lib/x86_64-linux-gnu/libgnutls.so.26.22.6)
==95176== by 0x63A0819: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63A0D29: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63A17EF: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63650DD: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63877F0: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x6388440: curl_multi_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x637FBA2: curl_easy_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x5F121B: zif_curl_exec (interface.c:2880)
==95176== by 0x9F2902: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==95176== by 0x9F2331: execute_ex (zend_vm_execute.h:414)
==95176== by 0x9F2443: zend_execute (zend_vm_execute.h:458)
==95176== Uninitialised value was created by a stack allocation
==95176== at 0x63A0100: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
Previous Comments:
------------------------------------------------------------------------
[2016-03-19 20:15:50] paul at salesintel dot com
I could not reopen the original bug # 71563
------------------------------------------------------------------------
[2016-03-19 20:14:32] paul at salesintel dot com
Description:
------------
When a couple of cURL options are set in a specific and valid way, and the curl.cainfo is set in
php.ini, curl_exec() never returns and PHP does not throw any exception, causing indefinite hang.
Same code in php 5.6.x (in each x32/x64 ts/nts) worked as expected.
In php 7.0.4 x32/x64 nts builds, hang occurs (ts versions not tried).
Test script:
---------------
FILE php.ini:
;change root path of your php accordingly
extension_dir = "C:\bin\php\7.0.4\nts-x32\ext\"
extension=php_curl.dll
curl.cainfo = "C:\bin\php\cacert.pem"
;cacert.pem downloaded from "https://curl.haxx.se/ca/cacert.pem"
FILE repro.php
<?php
repro();
function repro() {
$location = 'https://mail.microsoft.com/ews/exchange.asmx';
$request = str_repeat(' ', 1025);
$ch = curl_init($location);
curl_setopt($ch, CURLOPT_POSTFIELDS, $request);
curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC | CURLAUTH_NTLM);
curl_setopt($ch, CURLOPT_USERPWD, ' ');
$response = curl_exec($ch);
}
Expected result:
----------------
Call to curl_exec($ch) returns.
Actual result:
--------------
Call to curl_exec($ch) never returns.
However....
If you comment out the "curl.cainfo=" setting in php.ini, curl_exec($ch) returns.
If you change $location to an invalid endpoint or one that does not require NTLM, curl_exec()
returns.
If you remove the 'CURLAUTH_BASIC' leaving only 'CURLAUTH_NTLM', curl_exec()
returns;
If you remove 'CURLAUTH_NTLM' leaving only 'CURLAUTH_BASIC', curl_exec()
returns;
If you set an empty string ('') instead of one with one or more characters to
CURLOPT_USERPWD, curl_exec() returns.
$request is a string with 1025 characters. If you remove one character, leaving a (suspiciously
sized) 1024 character length $request, curl_exec($ch) returns.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71861&edit=1