Bug #81645 [NEW]: Integer overflow makes difference between HTTP status line and response code

From: Date: Sun, 21 Nov 2021 05:51:19 +0000
Subject: Bug #81645 [NEW]: Integer overflow makes difference between HTTP status line and response code
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237894@lists.php.net to get a copy of this message
From:             ive_jihwan at kaist dot ac dot kr
Operating system: Ubuntu 20.04
PHP version:      8.0.13
Package:          HTTP related
Bug Type:         Bug
Bug description:Integer overflow makes difference between HTTP status line and response code

Description:
------------
There is a special feature in header() function that updates both HTTP
status line and response code when the input is starts with "HTTP/"
(case insensitive),

header() function tries to parse the new HTTP status code from input
string by calling atoi() from the first non-whitespace substring after
string "HTTP/". And updates the response code as atoi()'s result, and
copies the HTTP status line to the raw response without any validation.

https://github.com/php/php-src/blob/master/main/SAPI.c#L550

This can cause following two problems.
1. Very wrong format of HTTP status line (which can cause variant
problems in browsers)
2. Mismatch of the SAPI response code and HTTP status line due to the
overflow of atoi



Test script:
---------------
<?php
header("HTTP/1.1 4294967496 aaa");

Expected result:
----------------
header() should be failed

Actual result:
--------------
(built-in PHP server)
[Sun Nov 21 05:39:04 2021] 127.0.0.1:43808 [200]: GET /sc
[Sun Nov 21 05:39:04 2021] 127.0.0.1:43808 Closing

(Raw HTTP response message)
HTTP/1.1 4294967496 aaa
Date: Sun, 21 Nov 2021 05:39:04 GMT
Connection: close
X-Powered-By: PHP/8.0.13
Content-type: text/html; charset=UTF-8

(curl)
$ curl localhost:1234/sc.php
curl: (1) Unsupported HTTP version in response

(Chrome)
https://imgur.com/a/DQT8qqZ

(Firefox)
https://imgur.com/naIbwVV

(Safari)
https://imgur.com/gtADjss



-- 
Edit bug report at https://bugs.php.net/bug.php?id=81645&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=81645&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=81645&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=81645&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=81645&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=81645&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=81645&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=81645&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=81645&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=81645&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=81645&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81645&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=81645&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=81645&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=81645&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=81645&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=81645&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=81645&r=mysqlcfg


Thread (15 messages)

« previous php.bugs (#237894) next »