Bug #78047 [Opn->Fbk]: [DoS] Segmentation fault through HTTP Requests
| From: | cmb@php.net | Date: | Fri, 30 Jul 2021 11:42:06 +0000 |
| Subject: | Bug #78047 [Opn->Fbk]: [DoS] Segmentation fault through HTTP Requests | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-235474@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78047&edit=1
ID: 78047
Updated by: cmb@php.net
Reported by: michele dot cisternino at protonmail dot com
Summary: [DoS] Segmentation fault through HTTP Requests
-Status: Open
+Status: Feedback
Type: Bug
Package: Built-in web server
Operating System: Linux
PHP Version: 7.3Git-2019-05-21 (snap)
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> It's just a bug, rofl.
If nobody can reproduce a reported bug, there may be no bug. ;)
Previous Comments:
------------------------------------------------------------------------
[2019-05-23 13:30:53] michele dot cisternino at protonmail dot com
It doesn't matter anymore :')
It's just a bug, rofl.
------------------------------------------------------------------------
[2019-05-23 09:25:52] nikic@php.net
I can't reproduce this on a 7.3 nts build. Also no warnings when running under valgrind.
------------------------------------------------------------------------
[2019-05-22 08:12:38] spam2 at rhsoft dot net
> can crash all the public instances of the built-in server
hopefully and then the people maybe read the first red box at https://www.php.net/manual/en/features.commandline.webserver.php
------------------------------------------------------------------------
[2019-05-22 07:57:44] michele dot cisternino at protonmail dot com
I disagree, respectfully.
A malicious user, thanks to this exploit, can crash all the public instances of the built-in server
(around 2.000, in my search).
Anyway, if you don't agree, I can disclose it (you also switched the status from Private to
Public), so we can see what the hacking community think about it.
Have a nice day :)
------------------------------------------------------------------------
[2019-05-22 07:40:34] cmb@php.net
To clarify: the built-in web server *can* of course be connected
to a public network; it is, however, not supposed to[1]. Therefore
we do not consider any issues related to the built-in web server
to be security issues.
[1] <https://www.php.net/manual/en/features.commandline.webserver.php>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=78047
--
Edit this bug report at https://bugs.php.net/bug.php?id=78047&edit=1