Bug #80849 [Opn->Ver]: HTTP Status header truncation

From: Date: Wed, 14 Jul 2021 12:52:01 +0000
Subject: Bug #80849 [Opn->Ver]: HTTP Status header truncation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235025@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80849&edit=1

 ID:                 80849
 Updated by:         cmb@php.net
 Reported by:        ben dot bidner at automattic dot com
 Summary:            HTTP Status header truncation
-Status:             Open
+Status:             Verified
 Type:               Bug
-Package:            FPM related
+Package:            CGI/CLI related
 PHP Version:        8.0.3
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2021-03-28 22:35:41] avinash dot roshan dot dsilva at gmail dot com

would the following change do the trick?

```
len = slprintf(buf, sizeof(buf)+2, "Status:%s\r\n",s);
```

------------------------------------------------------------------------
[2021-03-09 18:36:51] ben dot bidner at automattic dot com

Description:
------------
sapi_cgi_send_headers() (in both sapi/fpm/fpm/fpm_main.c and
sapi/cgi/cgi_main.c) will truncate HTTP Status headers larger than
SAPI_CGI_MAX_HEADER_LENGTH in the following cases, potentially causing the trailing CR
LF to be stripped.

	len = slprintf(buf, SAPI_CGI_MAX_HEADER_LENGTH, "%s\r\n",
SG(sapi_headers).http_status_line);
	len = slprintf(buf, sizeof(buf), "Status:%s\r\n", s);
	len = slprintf(buf, sizeof(buf), "Status: %d %s\r\n",
SG(sapi_headers).http_response_code, err->str);
	len = slprintf(buf, sizeof(buf), "Status: %d\r\n",
SG(sapi_headers).http_response_code);

Removing the CR LFs and explicitly sending them after the header is sent (as per other headers in
the code below this) should be sufficient to fix?

Test script:
---------------
<?php
header( 'HTTP/1.1 201 ' . str_repeat( 'A', 1011 ), true );
exit;

Actual result:
--------------
The example above will return the following headers

HTTP/1.1 201 AAA...AAAContent-type: text/html; charset=UTF-8
Server: nginx
Date: Tue, 09 Mar 2021 18:06:36 GMT
Connection: keep-alive


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80849&edit=1


Thread (5 messages)

« previous php.bugs (#235025) next »