Bug #78676 [NEW]: ldap_search() Can't contact LDAP server if user has larger jpegPhoto attribute
| From: | boris at brdaric dot com | Date: | Wed, 16 Oct 2019 09:35:12 +0000 |
| Subject: | Bug #78676 [NEW]: ldap_search() Can't contact LDAP server if user has larger jpegPhoto attribute | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-223214@lists.php.net to get a copy of this message | ||
From: boris at brdaric dot com
Operating system: Debian Linux
PHP version: 7.3.10
Package: LDAP related
Bug Type: Bug
Bug description:ldap_search() Can't contact LDAP server if user has larger jpegPhoto attribute
Description:
------------
Hello,
we are observing unexpected behaviour with ldap_search() function from
PHP-LDAP extension.
We have LDAP server where users can upload photos for their "profile"
picture.
That photo ends up in the "jpegPhoto" attribute.
If user has photo that is larger than ~15000 bytes (try with larger, eg.
1Mb photo ), ldap_search() unexpectedly returns "PHP Warning:
ldap_search(): Search: Can't contact LDAP server"
This unexpected behaviour occurs on
PHP 7.3.9 (Debian 10 Buster - PHP 7.3.9-1~deb10u1 (cli) (built: Sep 18
2019 10:33:23) ( NTS ))
PHP 7.3.10 (Debian 10 Buster - PHP
7.3.10-1+0~20191008.45+debian10~1.gbp365209 (cli) (built: Oct 8 2019
05:49:09) ( NTS ))
but NOT on
PHP 7.0.33 (Debian 9 Stretch - PHP 7.0.33-0+deb9u5 (cli) (built: Sep 18
2019 09:55:34) ( NTS ))
PHP 5.6.40 (Debian 8 Jessie - PHP 5.6.40-0+deb8u6 (cli) (built: Sep 15
2019 11:18:30))
--
ldapsearch command from ldap-utils Debian package works as expected on
all machines, printing all data to console
ldapsearch -x -LLL -h ldap.example.org -b"dc=example,dc=org" -s sub
"(uid=USERNAME)" // replace USERNAME with actual username
--
Test script is a slightly modified basic LDAP example from
https://www.php.net/manual/en/ldap.examples-basic.php
Test script:
---------------
usage php ldap-test.php [USERNAME] // fill USERNAME with actual
username
File name ldap-test.php
<?php
echo "LDAP query test\n";
echo "Connecting ...\n";
$ldap_server='ldaps://ldap.example.org'; // fill in actual data
$ldap_server_port='636'; // fill in actual data
$ds=ldap_connect($ldap_server, $ldap_server_port); // must be a valid
LDAP server!
echo "connect result is " . $ds . "\n";
if ($ds) {
echo "Binding ...\n";
$r=ldap_bind($ds); // this is an "anonymous" bind, typically
read-only access
echo "Bind result is " . $r . "\n";
echo "Searching...".$_SERVER['argv'][1]."\n";
/* Search surname entry */
$sr=ldap_search($ds, "dc=example, dc=org",
"uid=".$_SERVER['argv'][1]); // fill in actual dc
echo "Result:\n";
var_dump($sr);
if($sr){
echo "Data:\n";
$entries = ldap_get_entries($ds, $sr);
var_dump($entries);
}else {
echo "No results\n";
}
echo "Closing connection\n";
ldap_close($ds);
} else {
echo "Unable to connect to LDAP server\n";
}
Expected result:
----------------
$ php ldap-test.php bbrdaric1
LDAP query test
Connecting ...
connect result is Resource id #4
Binding ...
Bind result is 1
Searching...bbrdaric1
Result:
resource(5) of type (ldap result)
Data:
array(2) {
["count"]=>
int(1)
[0]=>
array(38) {
/* omitted for simplicity and privacy */
}
}
Closing connection
## User WITH jpegPhoto with 14995 bytes of data
$ php ldap-test.php bbrdaric2
LDAP query test
Connecting ...
connect result is Resource id #4
Binding ...
Bind result is 1
Searching...bbrdaric2
Result:
resource(5) of type (ldap result)
Data:
array(2) {
["count"]=>
int(1)
[0]=>
array(50) {
/* omitted for simplicity and privacy */
["jpegphoto"]=>
array(2) {
["count"]=>
int(1)
[0]=>
string(14995) "/* trimmed */"
}
}
}
Closing connection
Actual result:
--------------
## User WITH jpegPhoto with ~2MB data (that PHP Warning is unexpected)
$ php ldap-test.php bbrdaric3
LDAP query test
Connecting ...
connect result is Resource id #4
Binding ...
Bind result is 1
Searching...bbrdaric3
PHP Warning: ldap_search(): Search: Can't contact LDAP server in
/home/bbrdaric/ldap-test.php on line 20
Result:
bool(false)
No results
Closing connection
--
Edit bug report at https://bugs.php.net/bug.php?id=78676&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78676&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78676&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78676&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78676&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78676&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78676&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78676&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78676&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78676&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78676&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78676&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78676&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78676&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78676&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78676&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78676&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78676&r=mysqlcfg