Bug #70315 [NoF->Opn]: imagecreatefromstring() returns 500 Server Error but page full renderized

From: Date: Sun, 03 Jul 2016 04:47:51 +0000
Subject: Bug #70315 [NoF->Opn]: imagecreatefromstring() returns 500 Server Error but page full renderized
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202004@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70315&edit=1

 ID:                 70315
 Updated by:         requinix@php.net
 Reported by:        patriciotarantino at gmail dot com
 Summary:            imagecreatefromstring() returns 500 Server Error but
                     page full renderized
-Status:             No Feedback
+Status:             Open
 Type:               Bug
 Package:            GD related
 Operating System:   Ubuntu
 PHP Version:        5.6.12
 Assigned To:        cmb
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2016-07-03 04:22:20] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2016-06-27 19:22:24] razzari at gmail dot com

@cmb can repro in PHP version 5.5.35. 

@pajoye it's OK if the echo happens. The problem is that the page also includes an HTTP Error
500 header. Which is hugely wrong.

------------------------------------------------------------------------
[2016-06-22 07:19:55] pajoye@php.net

The header itself does not control the code execution.

The imagecreatefromstring returns false on error. That means the echo will happen.

It is the caller job to check the value and act accordingly. In case you expect the echo to never
happen on error, that's not the case using this piece of code.

------------------------------------------------------------------------
[2016-06-21 21:32:49] cmb@php.net

> If you use imagecreatefromstring() with an invalid string, it
> returns a 500 Internal Server Error in the HTTP headers, […]

Indeed, that is not supposed to happen, and I can't reproduce it,
actually. Please double-check with any of the recent PHP versions
(5.5.36, 5.6.22, 7.0.7).

------------------------------------------------------------------------
[2015-08-20 19:24:49] patriciotarantino at gmail dot com

Description:
------------
Condition: display_errors is off.

If you use imagecreatefromstring() with an invalid string, it returns a 500 Internal Server Error in
the HTTP headers, but the page is fully renderized. It should return 200 OK (and the full page), or
a 500 Error but without the full HTML. Not both at the same time.

5.3.10 and 5.4.44 are not affected.
5.5.9 and 5.6.12 are affected.

Test script:
---------------
<?php
ini_set("display_errors", 0);

$data = "iVBORw0KGgoAAAANSUhEUgAAAuwAAAUeCAYAAAAl3WR...LkAAAAAElFTkSuQmCC";
$data = base64_decode($data);
$im = imagecreatefromstring($data);

echo "This should not render";



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70315&edit=1


Thread (17 messages)

« previous php.bugs (#202004) next »