Bug #77141 [Ver->Csd]: Signedness issue in SOAP when precision=-1

From: Date: Mon, 12 Nov 2018 22:27:17 +0000
Subject: Bug #77141 [Ver->Csd]: Signedness issue in SOAP when precision=-1
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217921@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77141&edit=1

 ID:                 77141
 Updated by:         cmb@php.net
 Reported by:        lukasz dot jedrzejowski at adition dot com
 Summary:            Signedness issue in SOAP when precision=-1
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            SOAP related
 Operating System:   Debian GNU/Linux 9.5 (stretch)
 PHP Version:        7.1.24
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=f6079e3c56eabe03565faceaef9de12728d278bf
Log: Fix #77141: Signedness issue in SOAP when precision=-1


Previous Comments:
------------------------------------------------------------------------
[2018-11-12 17:33:07] cmb@php.net

Confirmed.  A -1 is passed to a size_t[1].

[1] <https://github.com/php/php-src/blob/php-7.3.0RC5/ext/soap/php_encoding.c#L1087>

------------------------------------------------------------------------
[2018-11-12 15:40:59] lukasz dot jedrzejowski at adition dot com

Description:
------------
Reproduced in:
- 7.1.23-2+0~20181015120514.8+stretch~1.gbpab65a0 (used this one as the nearest reported affected
version).
- 7.2.10-0ubuntu0.18.04.1
- 7.2.11-4+0~20181106031630.10+stretch~1.gbp789850
but worked correctly in:
- 5.6.24-0+deb8u1

Using -1 "precision" ini-setting on either SOAP request or response when passing a float
results in a fatal error: "Possible integer overflow in memory allocation".
Using other precision settings affects the string representation of passed floats as expected.

Although I've tested it manually on the SoapServer too, I'm providing the easier client
side steps to reproduce.

Test script was executed by running /tmp/test.php in cli mode.

Test script:
---------------
$soap = new \SoapClient(
    null,
    array(
        'location' => "http://localhost/soap.php",
        'uri' => "http://localhost/",
        'style' => SOAP_RPC,
        'trace' => true,
        'exceptions' => true,
    )
);
ini_set('precision', -1);
try {
    $soap->call(1.1);
} finally {
    echo $soap->__getLastRequest();
}

Expected result:
----------------
Expected to see the traced SOAP request with float represented as string according to the set
precision (for -1 precision the float 1.1 should be represented as "1.1").
Please ignore the additional "DTD are not supported" fatal error because of not actually
running a SoapServer under the given URI.
SOAP response output was shortened to avoid "spam detection" triggered by long lines when
reporting this bug.

...<SOAP-ENV:Body><ns1:call><param0
xsi:type="xsd:float">1.1</param0></ns1:call></SOAP-ENV:Body>...
PHP Fatal error:  Uncaught SoapFault exception: [Client] DTD are not supported by SOAP in
/tmp/test.php:14
Stack trace:
#0 /tmp/test.php(14): SoapClient->__call('call', Array)
#1 /tmp/test.php(14): SoapClient->call(1.1)
#2 {main}
  thrown in /tmp/test.php on line 14


Actual result:
--------------
PHP Fatal error:  Uncaught SoapFault exception: [Client] Possible integer overflow in memory
allocation (18446744073709551615 * 1 + 33) in /tmp/test.php:13
Stack trace:
#0 /tmp/test.php(13): SoapClient->__call('call', Array)
#1 {main}
  thrown in /tmp/test.php on line 13


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=77141&edit=1


Thread (3 messages)

« previous php.bugs (#217921) next »