Bug #77141 [Opn->Ver]: Integer overflow on SOAP request or response with -1 precision ini setting
| From: | cmb@php.net | Date: | Mon, 12 Nov 2018 17:33:07 +0000 |
| Subject: | Bug #77141 [Opn->Ver]: Integer overflow on SOAP request or response with -1 precision ini setting | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-217917@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77141&edit=1
ID: 77141
Updated by: cmb@php.net
Reported by: lukasz dot jedrzejowski at adition dot com
Summary: Integer overflow on SOAP request or response with -1
precision ini setting
-Status: Open
+Status: Verified
Type: Bug
Package: SOAP related
Operating System: Debian GNU/Linux 9.5 (stretch)
PHP Version: 7.1.24
Block user comment: N
Private report: N
New Comment:
Confirmed. A
-1 is passed to a size_t[1].
[1] <https://github.com/php/php-src/blob/php-7.3.0RC5/ext/soap/php_encoding.c#L1087>
Previous Comments:
------------------------------------------------------------------------
[2018-11-12 15:40:59] lukasz dot jedrzejowski at adition dot com
Description:
------------
Reproduced in:
- 7.1.23-2+0~20181015120514.8+stretch~1.gbpab65a0 (used this one as the nearest reported affected
version).
- 7.2.10-0ubuntu0.18.04.1
- 7.2.11-4+0~20181106031630.10+stretch~1.gbp789850
but worked correctly in:
- 5.6.24-0+deb8u1
Using -1 "precision" ini-setting on either SOAP request or response when passing a float
results in a fatal error: "Possible integer overflow in memory allocation".
Using other precision settings affects the string representation of passed floats as expected.
Although I've tested it manually on the SoapServer too, I'm providing the easier client
side steps to reproduce.
Test script was executed by running /tmp/test.php in cli mode.
Test script:
---------------
$soap = new \SoapClient(
null,
array(
'location' => "http://localhost/soap.php",
'uri' => "http://localhost/",
'style' => SOAP_RPC,
'trace' => true,
'exceptions' => true,
)
);
ini_set('precision', -1);
try {
$soap->call(1.1);
} finally {
echo $soap->__getLastRequest();
}
Expected result:
----------------
Expected to see the traced SOAP request with float represented as string according to the set
precision (for -1 precision the float 1.1 should be represented as "1.1").
Please ignore the additional "DTD are not supported" fatal error because of not actually
running a SoapServer under the given URI.
SOAP response output was shortened to avoid "spam detection" triggered by long lines when
reporting this bug.
...<SOAP-ENV:Body><ns1:call><param0
xsi:type="xsd:float">1.1</param0></ns1:call></SOAP-ENV:Body>...
PHP Fatal error: Uncaught SoapFault exception: [Client] DTD are not supported by SOAP in
/tmp/test.php:14
Stack trace:
#0 /tmp/test.php(14): SoapClient->__call('call', Array)
#1 /tmp/test.php(14): SoapClient->call(1.1)
#2 {main}
thrown in /tmp/test.php on line 14
Actual result:
--------------
PHP Fatal error: Uncaught SoapFault exception: [Client] Possible integer overflow in memory
allocation (18446744073709551615 * 1 + 33) in /tmp/test.php:13
Stack trace:
#0 /tmp/test.php(13): SoapClient->__call('call', Array)
#1 {main}
thrown in /tmp/test.php on line 13
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77141&edit=1