Bug #78047 [Fbk->NoF]: [DoS] Segmentation fault through HTTP Requests

From: Date: Sun, 08 Aug 2021 04:22:19 +0000
Subject: Bug #78047 [Fbk->NoF]: [DoS] Segmentation fault through HTTP Requests
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235675@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78047&edit=1 ID: 78047 Updated by: php-bugs@lists.php.net Reported by: michele dot cisternino at protonmail dot com Summary: [DoS] Segmentation fault through HTTP Requests -Status: Feedback +Status: No Feedback Type: Bug Package: Built-in web server Operating System: Linux PHP Version: 7.3Git-2019-05-21 (snap) Assigned To: cmb Private report: N New Comment: No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. Previous Comments: ------------------------------------------------------------------------ [2021-07-30 11:42:06] cmb@php.net > It's just a bug, rofl. If nobody can reproduce a reported bug, there may be no bug. ;) ------------------------------------------------------------------------ [2019-05-23 13:30:53] michele dot cisternino at protonmail dot com It doesn't matter anymore :') It's just a bug, rofl. ------------------------------------------------------------------------ [2019-05-23 09:25:52] nikic@php.net I can't reproduce this on a 7.3 nts build. Also no warnings when running under valgrind. ------------------------------------------------------------------------ [2019-05-22 08:12:38] spam2 at rhsoft dot net > can crash all the public instances of the built-in server hopefully and then the people maybe read the first red box at https://www.php.net/manual/en/features.commandline.webserver.php ------------------------------------------------------------------------ [2019-05-22 07:57:44] michele dot cisternino at protonmail dot com I disagree, respectfully. A malicious user, thanks to this exploit, can crash all the public instances of the built-in server (around 2.000, in my search). Anyway, if you don't agree, I can disclose it (you also switched the status from Private to Public), so we can see what the hacking community think about it. Have a nice day :) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=78047 -- Edit this bug report at https://bugs.php.net/bug.php?id=78047&edit=1

« previous php.bugs (#235675) next »