Bug #78200 [Com]: php-fpm doesn't prevent bogus Status-Line header to be send
| From: | loreydsyuyu322 at gmail dot com | Date: | Thu, 25 May 2023 11:51:15 +0000 |
| Subject: | Bug #78200 [Com]: php-fpm doesn't prevent bogus Status-Line header to be send | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-244530@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78200&edit=1
ID: 78200
Comment by: loreydsyuyu322 at gmail dot com
Reported by: vnsavage at gmail dot com
Summary: php-fpm doesn't prevent bogus Status-Line header to
be send
Status: Verified
Type: Bug
Package: *General Issues
Operating System: Debian
PHP Version: 7.2.19
Block user comment: N
Private report: N
New Comment:
That was so amazing. (https://www.myccpay.vip/)github.com
Previous Comments:
------------------------------------------------------------------------
[2019-06-27 12:01:36] sjon@php.net
nginx responds with "502 Bad Gateway" and logs
> upstream sent invalid status "Service Unavailable" while reading response header from
> upstream,
While this is documented as such, maybe the header should validated before being send out
------------------------------------------------------------------------
[2019-06-23 15:03:40] vnsavage at gmail dot com
Description:
------------
PHP-FPM will not validate that the HTTP status line set in PHP is correct as described in rfc2616.
Thus it will forward an incorrect CGI "Status:" response (which doesn't conform to
rfc3875).
Test script:
---------------
Set this incorrect header from PHP:
header( 'HTTP/1.1 Service Unavailable', true, 503 );
Then in sapi/fpm/fpm/fpm_main.c we have
len = slprintf(buf, sizeof(buf), "Status:%s\r\n", s);
which results in "Status: Service Unavailable" sent to the CGI socket.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78200&edit=1