Bug #77141 [Opn->Ver]: Integer overflow on SOAP request or response with -1 precision ini setting

From: Date: Mon, 12 Nov 2018 17:33:07 +0000
Subject: Bug #77141 [Opn->Ver]: Integer overflow on SOAP request or response with -1 precision ini setting
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217917@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77141&edit=1 ID: 77141 Updated by: cmb@php.net Reported by: lukasz dot jedrzejowski at adition dot com Summary: Integer overflow on SOAP request or response with -1 precision ini setting -Status: Open +Status: Verified Type: Bug Package: SOAP related Operating System: Debian GNU/Linux 9.5 (stretch) PHP Version: 7.1.24 Block user comment: N Private report: N New Comment: Confirmed. A -1 is passed to a size_t[1]. [1] <https://github.com/php/php-src/blob/php-7.3.0RC5/ext/soap/php_encoding.c#L1087> Previous Comments: ------------------------------------------------------------------------ [2018-11-12 15:40:59] lukasz dot jedrzejowski at adition dot com Description: ------------ Reproduced in: - 7.1.23-2+0~20181015120514.8+stretch~1.gbpab65a0 (used this one as the nearest reported affected version). - 7.2.10-0ubuntu0.18.04.1 - 7.2.11-4+0~20181106031630.10+stretch~1.gbp789850 but worked correctly in: - 5.6.24-0+deb8u1 Using -1 "precision" ini-setting on either SOAP request or response when passing a float results in a fatal error: "Possible integer overflow in memory allocation". Using other precision settings affects the string representation of passed floats as expected. Although I've tested it manually on the SoapServer too, I'm providing the easier client side steps to reproduce. Test script was executed by running /tmp/test.php in cli mode. Test script: --------------- $soap = new \SoapClient( null, array( 'location' => "http://localhost/soap.php", 'uri' => "http://localhost/", 'style' => SOAP_RPC, 'trace' => true, 'exceptions' => true, ) ); ini_set('precision', -1); try { $soap->call(1.1); } finally { echo $soap->__getLastRequest(); } Expected result: ---------------- Expected to see the traced SOAP request with float represented as string according to the set precision (for -1 precision the float 1.1 should be represented as "1.1"). Please ignore the additional "DTD are not supported" fatal error because of not actually running a SoapServer under the given URI. SOAP response output was shortened to avoid "spam detection" triggered by long lines when reporting this bug. ...<SOAP-ENV:Body><ns1:call><param0 xsi:type="xsd:float">1.1</param0></ns1:call></SOAP-ENV:Body>... PHP Fatal error: Uncaught SoapFault exception: [Client] DTD are not supported by SOAP in /tmp/test.php:14 Stack trace: #0 /tmp/test.php(14): SoapClient->__call('call', Array) #1 /tmp/test.php(14): SoapClient->call(1.1) #2 {main} thrown in /tmp/test.php on line 14 Actual result: -------------- PHP Fatal error: Uncaught SoapFault exception: [Client] Possible integer overflow in memory allocation (18446744073709551615 * 1 + 33) in /tmp/test.php:13 Stack trace: #0 /tmp/test.php(13): SoapClient->__call('call', Array) #1 {main} thrown in /tmp/test.php on line 13 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77141&edit=1

« previous php.bugs (#217917) next »