Bug #71861 [Opn]: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang
| From: | paul at salesintel dot com | Date: | Sun, 20 Mar 2016 13:27:01 +0000 |
| Subject: | Bug #71861 [Opn]: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec() causing hang | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-199964@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71861&edit=1
ID: 71861
User updated by: paul at salesintel dot com
Reported by: paul at salesintel dot com
Summary: RE-OPENED, MORE INFO, Buffer Overrun in curl_exec()
causing hang
Status: Open
Type: Bug
Package: cURL related
Operating System: Windows 10 x64
PHP Version: 7.0.4
Block user comment: N
Private report: N
New Comment:
If the curl library is different between 5.6 and 7.0, than maybe there's a bug in curl; there
is no hanging when running repro() in 5.6 as noted in the original bug report.
However, I would be surprised curl is coupling anything of their implementation to php cadence, and
given the significant change in memory management and access between 5.6 and 7.0, and that the
exception is saying something is uninitialized, I would think it more likely there's something
the 7.0 curl wrapper is doing differently that is the underlying cause, and the exception occurring
in the curl library is merely a symptom of it.
curl_exec() requires certain state to be configured before it's called, and that state is being
set through the php curl wrapper, which could be de-allocating or moving something around between
the state setting calls curl_init() & curl_setop(), and the curl_exec() call. What's also
suspect is that minor changes to several different curl_setop() arguments can either expose or hide
the problem.
I'm saying all this in hopes this issue isn't being 'punted' over to there being
something wrong with curl, without first empirically ruling out php, given the aforementioned
observations.
Previous Comments:
------------------------------------------------------------------------
[2016-03-20 12:41:24] laruence@php.net
Seems like a curl bug?
==95176== Conditional jump or move depends on uninitialised value(s)
==95176== at 0x79128CD: gnutls_session_get_data (in
/usr/lib/x86_64-linux-gnu/libgnutls.so.26.22.6)
==95176== by 0x63A0819: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63A0D29: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63A17EF: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63650DD: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x63877F0: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x6388440: curl_multi_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x637FBA2: curl_easy_perform (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
==95176== by 0x5F121B: zif_curl_exec (interface.c:2880)
==95176== by 0x9F2902: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:586)
==95176== by 0x9F2331: execute_ex (zend_vm_execute.h:414)
==95176== by 0x9F2443: zend_execute (zend_vm_execute.h:458)
==95176== Uninitialised value was created by a stack allocation
==95176== at 0x63A0100: ??? (in /usr/lib/x86_64-linux-gnu/libcurl-gnutls.so.4.3.0)
------------------------------------------------------------------------
[2016-03-19 20:15:50] paul at salesintel dot com
I could not reopen the original bug # 71563
------------------------------------------------------------------------
[2016-03-19 20:14:32] paul at salesintel dot com
Description:
------------
When a couple of cURL options are set in a specific and valid way, and the curl.cainfo is set in
php.ini, curl_exec() never returns and PHP does not throw any exception, causing indefinite hang.
Same code in php 5.6.x (in each x32/x64 ts/nts) worked as expected.
In php 7.0.4 x32/x64 nts builds, hang occurs (ts versions not tried).
Test script:
---------------
FILE php.ini:
;change root path of your php accordingly
extension_dir = "C:\bin\php\7.0.4\nts-x32\ext\"
extension=php_curl.dll
curl.cainfo = "C:\bin\php\cacert.pem"
;cacert.pem downloaded from "https://curl.haxx.se/ca/cacert.pem"
FILE repro.php
<?php
repro();
function repro() {
$location = 'https://mail.microsoft.com/ews/exchange.asmx';
$request = str_repeat(' ', 1025);
$ch = curl_init($location);
curl_setopt($ch, CURLOPT_POSTFIELDS, $request);
curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_BASIC | CURLAUTH_NTLM);
curl_setopt($ch, CURLOPT_USERPWD, ' ');
$response = curl_exec($ch);
}
Expected result:
----------------
Call to curl_exec($ch) returns.
Actual result:
--------------
Call to curl_exec($ch) never returns.
However....
If you comment out the "curl.cainfo=" setting in php.ini, curl_exec($ch) returns.
If you change $location to an invalid endpoint or one that does not require NTLM, curl_exec()
returns.
If you remove the 'CURLAUTH_BASIC' leaving only 'CURLAUTH_NTLM', curl_exec()
returns;
If you remove 'CURLAUTH_NTLM' leaving only 'CURLAUTH_BASIC', curl_exec()
returns;
If you set an empty string ('') instead of one with one or more characters to
CURLOPT_USERPWD, curl_exec() returns.
$request is a string with 1025 characters. If you remove one character, leaving a (suspiciously
sized) 1024 character length $request, curl_exec($ch) returns.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71861&edit=1