Bug #71861 [Opn]: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang

From: Date: Sun, 20 Mar 2016 12:41:26 +0000
Subject: Bug #71861 [Opn]: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199958@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71861&edit=1 ID: 71861 Updated by: laruence@php.net Reported by: paul at salesintel dot com Summary: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang Status: Open Type: Bug Package: cURL related Operating System: Windows 10 x64 PHP Version: 7.0.4 Block user comment: N Private report: N New Comment: Seems like a curl bug? ==95176== Conditional jump or move depends on uninitialised value(s) ==95176== at 0x79128CD: gnutls_session_get_data (in /usr/lib/x86_64-linux-gnu/libgnutls.so.26.22.6) ==95176== by 0x63A0819: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x63A0D29: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x63A17EF: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x63650DD: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x63877F0: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x6388440: curl_multi_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x637FBA2: curl_easy_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) ==95176== by 0x5F121B: zif_curl_exec (interface.c:2880) ==95176== by 0x9F2902: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586) ==95176== by 0x9F2331: execute_ex (zend_vm_execute.h:414) ==95176== by 0x9F2443: zend_execute (zend_vm_execute.h:458) ==95176== Uninitialised value was created by a stack allocation ==95176== at 0x63A0100: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0) Previous Comments: ------------------------------------------------------------------------ [2016-03-19 20:15:50] paul at salesintel dot com I could not reopen the original bug # 71563 ------------------------------------------------------------------------ [2016-03-19 20:14:32] paul at salesintel dot com Description: ------------ When a couple of cURL options are set in a specific and valid way, and the curl.cainfo is set in php.ini, curl_exec() never returns and PHP does not throw any exception, causing indefinite hang. Same code in php 5.6.x (in each x32/x64 ts/nts) worked as expected. In php 7.0.4 x32/x64 nts builds, hang occurs (ts versions not tried). Test script: --------------- FILE php.ini: ;change root path of your php accordingly extension_dir = "C:\bin\php\7.0.4\nts-x32\ext\" extension=php_curl.dll curl.cainfo = "C:\bin\php\cacert.pem" ;cacert.pem downloaded from "https://curl.haxx.se/ca/cacert.pem" FILE repro.php <?php repro(); function repro() { $location = 'https://mail.microsoft.com/ews/exchange.asmx'; $request = str_repeat(' ', 1025); $ch = curl_init($location); curl_setopt($ch, CURLOPT_POSTFIELDS, $request); curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC | CURLAUTH_NTLM); curl_setopt($ch, CURLOPT_USERPWD, ' '); $response = curl_exec($ch); } Expected result: ---------------- Call to curl_exec($ch) returns. Actual result: -------------- Call to curl_exec($ch) never returns. However.... If you comment out the "curl.cainfo=" setting in php.ini, curl_exec($ch) returns. If you change $location to an invalid endpoint or one that does not require NTLM, curl_exec() returns. If you remove the 'CURLAUTH_BASIC' leaving only 'CURLAUTH_NTLM', curl_exec() returns; If you remove 'CURLAUTH_NTLM' leaving only 'CURLAUTH_BASIC', curl_exec() returns; If you set an empty string ('') instead of one with one or more characters to CURLOPT_USERPWD, curl_exec() returns. $request is a string with 1025 characters. If you remove one character, leaving a (suspiciously sized) 1024 character length $request, curl_exec($ch) returns. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71861&edit=1

« previous php.bugs (#199958) next »