Bug #74408 [Opn->Csd]: Endless loop bypassing execution time limit

From: Date: Tue, 11 Apr 2017 10:47:18 +0000
Subject: Bug #74408 [Opn->Csd]: Endless loop bypassing execution time limit
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208475@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74408&edit=1

 ID:                 74408
 Updated by:         laruence@php.net
 Reported by:        andy_2639 at justmail dot de
 Summary:            Endless loop bypassing execution time limit
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Windows 10 Pro x64
 PHP Version:        7.1.3
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=eb03f16442c7ee10842dde0140b933d2be60b84b
Log: Fixed bug #74408 (Endless loop bypassing execution time limit)


Previous Comments:
------------------------------------------------------------------------
[2017-04-10 17:46:30] andy_2639 at justmail dot de

Description:
------------
The test script hangs with eating one core completely. Even after the execution time limit is
exceeded, php does not abort.
I had to kill php-cgi.exe via task manager.

This might allow DoS attacks to shared hosters where an attacker can upload its own code.

I guess that there is a ping-pong between the error_handler and the exception_handler (deprecation
warning of static call to non-static method and instanciating an object of unknown class).

Test script:
---------------
<?php

// php.ini: error_reporting = E_ALL | E_DEPRECATED | E_STRICT

 class ErrorHandling {

  public function error_handler(int $errno, string $errstr, string $errfile, int $errline): void {
   $bla = new NonExistingClass2();
  }

  public function exception_handler(Throwable $e): void { }

 }

 set_error_handler('ErrorHandling::error_handler');
 set_exception_handler('ErrorHandling::exception_handler');

 $blubb = new NonExistingClass();


Expected result:
----------------
Best case: printing an error message and stopping the script.

At least I expect the script to be aborted after the execution time limit exceeds.

Actual result:
--------------
PHP runs eating a core fully without increasing its memory need until I kill php-cgi.exe via task
manager.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=74408&edit=1


Thread (1 message)

  • laruence@php.net
  • Unknown Message
    • laruence@php.net
« previous php.bugs (#208475) next »