#13455 [Sus->]: Using include() with Apache ErrorDocument directive can crash the webserver
| From: | sniper@php.net | Date: | Sat, 07 Dec 2002 01:56:16 +0000 |
| Subject: | #13455 [Sus->]: Using include() with Apache ErrorDocument directive can crash the webserver | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-26921@lists.php.net to get a copy of this message | ||
ID: 13455
Updated by: sniper@php.net
Reported By: manitu@manitu.net
-Status: Suspended
+Status: Won\'t fix
Bug Type: Scripting Engine problem
Operating System: Any Linux with any Apache
PHP Version: 4.0.6
Previous Comments:
------------------------------------------------------------------------
[2001-12-14 14:10:24] yohgaki@php.net
I understand what you've explained. But I'll set status to Suspended.
Please work around this problem.
------------------------------------------------------------------------
[2001-09-26 12:37:33] manitu@manitu.net
HOW TO REPRODUCE
1. You must run Apache in any version on a Linux system and have setup
an VirtualHost entry with
an example domain "www.domain.com".
2. Configure an .htaccess file like
ErrorDocument 404 http://www.domain.com/notfound.html
3. The notfound.html file MUST NOT exist and you MUST use an external
path
4. Write a php script like
<?php
include("http://www.domain.com/any_file_that_does_not_exist.html");
?>
WHAT HAPPENS
The include() function tries to get the specified document but cannot
find it. So the Apache webserver
sends an 404 error together with a HTTP redirection. The include()
tries to catch this address which
leads into an infinite loop. The webserver will die shortly.
HOW TO SOLVE
The include() function should have a limit on how many levels it tries
to catch since the webserver is not
able to determine if the caller runs into an infinite loop.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=13455&edit=1