Bug->Req #81645 [Opn]: header() allows arbitrary status codes (which may overflow)

From: Date: Mon, 22 Nov 2021 15:26:19 +0000
Subject: Bug->Req #81645 [Opn]: header() allows arbitrary status codes (which may overflow)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-237918@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81645&edit=1

 ID:                 81645
 Updated by:         cmb@php.net
 Reported by:        ive_jihwan at kaist dot ac dot kr
-Summary:            Integer overflow makes difference between HTTP
                     status line and response code
+Summary:            header() allows arbitrary status codes (which may
                     overflow)
 Status:             Open
-Type:               Bug
+Type:               Feature/Change Request
 Package:            HTTP related
 Operating System:   Ubuntu 20.04
 PHP Version:        8.0.13
 Block user comment: N
 Private report:     N

 New Comment:

I can reproduce even with the HTTP version (e.g. HTTP/1.1).
However, while I agree that the parsing is sloppy, I don't see
this as a real bug.  After all, HTTP status codes are supposed to
consist of three digits[1], and passing arbitrary status codes is
just not caught by PHP.  There is not much to prevent us from
improving the current behavior, though.  A pull request[2] would
be welcome!

[1] <https://datatracker.ietf.org/doc/html/rfc7230#section-3.1.2>
[2] <https://github.com/php/php-src#contributing>


Previous Comments:
------------------------------------------------------------------------
[2021-11-21 05:59:56] ive_jihwan at kaist dot ac dot kr

There was a mistake in writing a report, During all of report, HTTP version must be missing. Thus,
Test script should be changed to 

<?php
header("HTTP/ 4294967496 aaa");

and actual result from raw response message also must be changed to
HTTP/ 4294967496 aaa
Date: Sun, 21 Nov 2021 05:39:04 GMT
Connection: close
X-Powered-By: PHP/8.0.13
Content-type: text/html; charset=UTF-8

------------------------------------------------------------------------
[2021-11-21 05:51:19] ive_jihwan at kaist dot ac dot kr

Description:
------------
There is a special feature in header() function that updates both HTTP status line and response code
when the input is starts with "HTTP/" (case insensitive),

header() function tries to parse the new HTTP status code from input string by calling atoi() from
the first non-whitespace substring after string "HTTP/". And updates the response code as
atoi()'s result, and copies the HTTP status line to the raw response without any validation.

https://github.com/php/php-src/blob/master/main/SAPI.c#L550

This can cause following two problems.
1. Very wrong format of HTTP status line (which can cause variant problems in browsers)
2. Mismatch of the SAPI response code and HTTP status line due to the overflow of atoi



Test script:
---------------
<?php
header("HTTP/1.1 4294967496 aaa");

Expected result:
----------------
header() should be failed

Actual result:
--------------
(built-in PHP server)
[Sun Nov 21 05:39:04 2021] 127.0.0.1:43808 [200]: GET /sc
[Sun Nov 21 05:39:04 2021] 127.0.0.1:43808 Closing

(Raw HTTP response message)
HTTP/1.1 4294967496 aaa
Date: Sun, 21 Nov 2021 05:39:04 GMT
Connection: close
X-Powered-By: PHP/8.0.13
Content-type: text/html; charset=UTF-8

(curl)
$ curl localhost:1234/sc.php
curl: (1) Unsupported HTTP version in response

(Chrome)
https://imgur.com/a/DQT8qqZ

(Firefox)
https://imgur.com/naIbwVV

(Safari)
https://imgur.com/gtADjss




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=81645&edit=1


Thread (15 messages)

« previous php.bugs (#237918) next »