Bug #70315 [Com]: imagecreatefromstring() returns 500 Server Error but page full renderized

From: Date: Mon, 27 Jun 2016 19:22:25 +0000
Subject: Bug #70315 [Com]: imagecreatefromstring() returns 500 Server Error but page full renderized
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201876@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70315&edit=1

 ID:                 70315
 Comment by:         razzari at gmail dot com
 Reported by:        patriciotarantino at gmail dot com
 Summary:            imagecreatefromstring() returns 500 Server Error but
                     page full renderized
 Status:             Feedback
 Type:               Bug
 Package:            GD related
 Operating System:   Ubuntu
 PHP Version:        5.6.12
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

@cmb can repro in PHP version 5.5.35. 

@pajoye it's OK if the echo happens. The problem is that the page also includes an HTTP Error
500 header. Which is hugely wrong.


Previous Comments:
------------------------------------------------------------------------
[2016-06-22 07:19:55] pajoye@php.net

The header itself does not control the code execution.

The imagecreatefromstring returns false on error. That means the echo will happen.

It is the caller job to check the value and act accordingly. In case you expect the echo to never
happen on error, that's not the case using this piece of code.

------------------------------------------------------------------------
[2016-06-21 21:32:49] cmb@php.net

> If you use imagecreatefromstring() with an invalid string, it
> returns a 500 Internal Server Error in the HTTP headers, […]

Indeed, that is not supposed to happen, and I can't reproduce it,
actually. Please double-check with any of the recent PHP versions
(5.5.36, 5.6.22, 7.0.7).

------------------------------------------------------------------------
[2015-08-20 19:24:49] patriciotarantino at gmail dot com

Description:
------------
Condition: display_errors is off.

If you use imagecreatefromstring() with an invalid string, it returns a 500 Internal Server Error in
the HTTP headers, but the page is fully renderized. It should return 200 OK (and the full page), or
a 500 Error but without the full HTML. Not both at the same time.

5.3.10 and 5.4.44 are not affected.
5.5.9 and 5.6.12 are affected.

Test script:
---------------
<?php
ini_set("display_errors", 0);

$data = "iVBORw0KGgoAAAANSUhEUgAAAuwAAAUeCAYAAAAl3WR...LkAAAAAElFTkSuQmCC";
$data = base64_decode($data);
$im = imagecreatefromstring($data);

echo "This should not render";



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70315&edit=1


Thread (17 messages)

« previous php.bugs (#201876) next »