#13455 [Sus->]: Using include() with Apache ErrorDocument directive can crash the webserver

From: Date: Sat, 07 Dec 2002 01:56:16 +0000
Subject: #13455 [Sus->]: Using include() with Apache ErrorDocument directive can crash the webserver
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-26921@lists.php.net to get a copy of this message
ID: 13455 Updated by: sniper@php.net Reported By: manitu@manitu.net -Status: Suspended +Status: Won\'t fix Bug Type: Scripting Engine problem Operating System: Any Linux with any Apache PHP Version: 4.0.6 Previous Comments: ------------------------------------------------------------------------ [2001-12-14 14:10:24] yohgaki@php.net I understand what you've explained. But I'll set status to Suspended. Please work around this problem. ------------------------------------------------------------------------ [2001-09-26 12:37:33] manitu@manitu.net HOW TO REPRODUCE 1. You must run Apache in any version on a Linux system and have setup an VirtualHost entry with an example domain "www.domain.com". 2. Configure an .htaccess file like ErrorDocument 404 http://www.domain.com/notfound.html 3. The notfound.html file MUST NOT exist and you MUST use an external path 4. Write a php script like <?php include("http://www.domain.com/any_file_that_does_not_exist.html"); ?> WHAT HAPPENS The include() function tries to get the specified document but cannot find it. So the Apache webserver sends an 404 error together with a HTTP redirection. The include() tries to catch this address which leads into an infinite loop. The webserver will die shortly. HOW TO SOLVE The include() function should have a limit on how many levels it tries to catch since the webserver is not able to determine if the caller runs into an infinite loop. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=13455&edit=1

« previous php.bugs (#26921) next »