Bug #78047 [Opn->Fbk]: [DoS] Segmentation fault through HTTP Requests

From: Date: Fri, 30 Jul 2021 11:42:06 +0000
Subject: Bug #78047 [Opn->Fbk]: [DoS] Segmentation fault through HTTP Requests
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235474@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78047&edit=1 ID: 78047 Updated by: cmb@php.net Reported by: michele dot cisternino at protonmail dot com Summary: [DoS] Segmentation fault through HTTP Requests -Status: Open +Status: Feedback Type: Bug Package: Built-in web server Operating System: Linux PHP Version: 7.3Git-2019-05-21 (snap) -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: > It's just a bug, rofl. If nobody can reproduce a reported bug, there may be no bug. ;) Previous Comments: ------------------------------------------------------------------------ [2019-05-23 13:30:53] michele dot cisternino at protonmail dot com It doesn't matter anymore :') It's just a bug, rofl. ------------------------------------------------------------------------ [2019-05-23 09:25:52] nikic@php.net I can't reproduce this on a 7.3 nts build. Also no warnings when running under valgrind. ------------------------------------------------------------------------ [2019-05-22 08:12:38] spam2 at rhsoft dot net > can crash all the public instances of the built-in server hopefully and then the people maybe read the first red box at https://www.php.net/manual/en/features.commandline.webserver.php ------------------------------------------------------------------------ [2019-05-22 07:57:44] michele dot cisternino at protonmail dot com I disagree, respectfully. A malicious user, thanks to this exploit, can crash all the public instances of the built-in server (around 2.000, in my search). Anyway, if you don't agree, I can disclose it (you also switched the status from Private to Public), so we can see what the hacking community think about it. Have a nice day :) ------------------------------------------------------------------------ [2019-05-22 07:40:34] cmb@php.net To clarify: the built-in web server *can* of course be connected to a public network; it is, however, not supposed to[1]. Therefore we do not consider any issues related to the built-in web server to be security issues. [1] <https://www.php.net/manual/en/features.commandline.webserver.php> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78047 -- Edit this bug report at https://bugs.php.net/bug.php?id=78047&edit=1

« previous php.bugs (#235474) next »