Bug #80849 [Ver->Csd]: HTTP Status header truncation

From: Date: Thu, 15 Jul 2021 17:18:32 +0000
Subject: Bug #80849 [Ver->Csd]: HTTP Status header truncation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235065@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80849&edit=1 ID: 80849 Updated by: git@php.net Reported by: ben dot bidner at automattic dot com Summary: HTTP Status header truncation -Status: Verified +Status: Closed Type: Bug Package: CGI/CLI related PHP Version: 8.0.3 Assigned To: cmb Block user comment: N Private report: N New Comment: Automatic comment on behalf of cmb69 Revision: https://github.com/php/php-src/commit/a054ef2aadd52238eb85d2e4c2b2b989e554a705 Log: Fix #80849: HTTP Status header truncation Previous Comments: ------------------------------------------------------------------------ [2021-07-14 12:52:22] cmb@php.net The following pull request has been associated: Patch Name: Fix #80849: HTTP Status header truncation On GitHub: https://github.com/php/php-src/pull/7238 Patch: https://github.com/php/php-src/pull/7238.patch ------------------------------------------------------------------------ [2021-03-28 22:35:41] avinash dot roshan dot dsilva at gmail dot com would the following change do the trick? ``` len = slprintf(buf, sizeof(buf)+2, "Status:%s\r\n",s); ``` ------------------------------------------------------------------------ [2021-03-09 18:36:51] ben dot bidner at automattic dot com Description: ------------ sapi_cgi_send_headers() (in both sapi/fpm/fpm/fpm_main.c and sapi/cgi/cgi_main.c) will truncate HTTP Status headers larger than SAPI_CGI_MAX_HEADER_LENGTH in the following cases, potentially causing the trailing CR LF to be stripped. len = slprintf(buf, SAPI_CGI_MAX_HEADER_LENGTH, "%s\r\n", SG(sapi_headers).http_status_line); len = slprintf(buf, sizeof(buf), "Status:%s\r\n", s); len = slprintf(buf, sizeof(buf), "Status: %d %s\r\n", SG(sapi_headers).http_response_code, err->str); len = slprintf(buf, sizeof(buf), "Status: %d\r\n", SG(sapi_headers).http_response_code); Removing the CR LFs and explicitly sending them after the header is sent (as per other headers in the code below this) should be sufficient to fix? Test script: --------------- <?php header( 'HTTP/1.1 201 ' . str_repeat( 'A', 1011 ), true ); exit; Actual result: -------------- The example above will return the following headers HTTP/1.1 201 AAA...AAAContent-type: text/html; charset=UTF-8 Server: nginx Date: Tue, 09 Mar 2021 18:06:36 GMT Connection: keep-alive ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80849&edit=1

« previous php.bugs (#235065) next »