Bug #81645 [NEW]: Integer overflow makes difference between HTTP status line and response code
From: ive_jihwan at kaist dot ac dot kr
Operating system: Ubuntu 20.04
PHP version: 8.0.13
Package: HTTP related
Bug Type: Bug
Bug description:Integer overflow makes difference between HTTP status line and response code
Description:
------------
There is a special feature in header() function that updates both HTTP
status line and response code when the input is starts with "HTTP/"
(case insensitive),
header() function tries to parse the new HTTP status code from input
string by calling atoi() from the first non-whitespace substring after
string "HTTP/". And updates the response code as atoi()'s result, and
copies the HTTP status line to the raw response without any validation.
https://github.com/php/php-src/blob/master/main/SAPI.c#L550
This can cause following two problems.
1. Very wrong format of HTTP status line (which can cause variant
problems in browsers)
2. Mismatch of the SAPI response code and HTTP status line due to the
overflow of atoi
Test script:
---------------
<?php
header("HTTP/1.1 4294967496 aaa");
Expected result:
----------------
header() should be failed
Actual result:
--------------
(built-in PHP server)
[Sun Nov 21 05:39:04 2021] 127.0.0.1:43808 [200]: GET /sc
[Sun Nov 21 05:39:04 2021] 127.0.0.1:43808 Closing
(Raw HTTP response message)
HTTP/1.1 4294967496 aaa
Date: Sun, 21 Nov 2021 05:39:04 GMT
Connection: close
X-Powered-By: PHP/8.0.13
Content-type: text/html; charset=UTF-8
(curl)
$ curl localhost:1234/sc.php
curl: (1) Unsupported HTTP version in response
(Chrome)
https://imgur.com/a/DQT8qqZ
(Firefox)
https://imgur.com/naIbwVV
(Safari)
https://imgur.com/gtADjss
--
Edit bug report at https://bugs.php.net/bug.php?id=81645&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=81645&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=81645&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=81645&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=81645&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=81645&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=81645&r=support
Expected behavior: https://bugs.php.net/fix.php?id=81645&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=81645&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=81645&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=81645&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=81645&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=81645&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=81645&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=81645&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=81645&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=81645&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=81645&r=mysqlcfg
Thread (15 messages)
- ive_jihwan at kaist dot ac dot kr
- ive_jihwan at kaist dot ac dot krBug #81645 [Opn]: Integer overflow makes difference between HTTP status line and response code
- cmb@php.netBug->Req #81645 [Opn]: header() allows arbitrary status codes (which may overflow)
- ive_jihwan at kaist dot ac dot krReq #81645 [Opn]: header() allows arbitrary status codes (which may overflow)
- ive_jihwan@kaist.ac.krReq #81645 [PATCH]: header() allows arbitrary status codes (which may overflow)
- fariba dot shami326 at gmail dot comReq #81645 [Com]: header() allows arbitrary status codes (which may overflow)
- robsonldspj11 at gmail dot comReq #81645 [Com]: header() allows arbitrary status codes (which may overflow)
- sample@email.tstReq #81645 [PATCH]: header() allows arbitrary status codes (which may overflow)
- sample@email.tstReq #81645 [PATCH]: header() allows arbitrary status codes (which may overflow)
- sample@email.tstReq #81645 [PATCH]: header() allows arbitrary status codes (which may overflow)
- sample@email.tstReq #81645 [PATCH]: header() allows arbitrary status codes (which may overflow)
- sample@email.tstReq #81645 [PATCH]: header() allows arbitrary status codes (which may overflow)
- stevewilaon34 at aol dot comReq #81645 [Com]: header() allows arbitrary status codes (which may overflow)
- James120 at aol dot comReq #81645 [Com]: header() allows arbitrary status codes (which may overflow)
- kevinwest at aol dot comReq #81645 [Com]: header() allows arbitrary status codes (which may overflow)