Req #81645 [Com]: header() allows arbitrary status codes (which may overflow)

From: Date: Sat, 24 Dec 2022 09:06:13 +0000
Subject: Req #81645 [Com]: header() allows arbitrary status codes (which may overflow)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-243240@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81645&edit=1

 ID:                 81645
 Comment by:         robsonldspj11 at gmail dot com
 Reported by:        ive_jihwan at kaist dot ac dot kr
 Summary:            header() allows arbitrary status codes (which may
                     overflow)
 Status:             Open
 Type:               Feature/Change Request
 Package:            HTTP related
 Operating System:   Ubuntu 20.04
 PHP Version:        8.0.13
 Block user comment: N
 Private report:     N

 New Comment:

I'm especially stayed aware of the article and I will get many benefits from it. Subsequently,
thank you for sharing it. (https://www.9wsyr.me/)github.com


Previous Comments:
------------------------------------------------------------------------
[2022-12-20 08:08:03] fariba dot shami326 at gmail dot com

You should definitely report that issue and assign to developer. And if there is no developer
present and you have to deliver the build, then deliver build and mention the issue as known issue.

(https://www.bookiemarket.net/)php.net

------------------------------------------------------------------------
[2021-11-23 08:35:37] ive_jihwan at kaist dot ac dot kr

The following pull request has been associated:

Patch Name: Update #81645 : header() checks the validity of HTTP status code
On GitHub:  https://github.com/php/php-src/pull/7676
Patch:      https://github.com/php/php-src/pull/7676.patch

------------------------------------------------------------------------
[2021-11-22 15:39:30] ive_jihwan at kaist dot ac dot kr

Thanks for reply!

Then I'm going to write a fix of it and let me make a PR :)

------------------------------------------------------------------------
[2021-11-22 15:26:19] cmb@php.net

I can reproduce even with the HTTP version (e.g. HTTP/1.1).
However, while I agree that the parsing is sloppy, I don't see
this as a real bug.  After all, HTTP status codes are supposed to
consist of three digits[1], and passing arbitrary status codes is
just not caught by PHP.  There is not much to prevent us from
improving the current behavior, though.  A pull request[2] would
be welcome!

[1] <https://datatracker.ietf.org/doc/html/rfc7230#section-3.1.2>
[2] <https://github.com/php/php-src#contributing>

------------------------------------------------------------------------
[2021-11-21 05:59:56] ive_jihwan at kaist dot ac dot kr

There was a mistake in writing a report, During all of report, HTTP version must be missing. Thus,
Test script should be changed to 

<?php
header("HTTP/ 4294967496 aaa");

and actual result from raw response message also must be changed to
HTTP/ 4294967496 aaa
Date: Sun, 21 Nov 2021 05:39:04 GMT
Connection: close
X-Powered-By: PHP/8.0.13
Content-type: text/html; charset=UTF-8

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=81645


--
Edit this bug report at https://bugs.php.net/bug.php?id=81645&edit=1


Thread (15 messages)

« previous php.bugs (#243240) next »