#22508 [Csd]: fopen() crashes Apache if URL is redirect/

From: Date: Fri, 18 Apr 2003 05:24:34 +0000
Subject: #22508 [Csd]: fopen() crashes Apache if URL is redirect/
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-37837@lists.php.net to get a copy of this message
ID: 22508 User updated by: jim at bluedojo dot com Reported By: jim at bluedojo dot com Status: Closed Bug Type: *Directory/Filesystem functions Operating System: Windows PHP Version: 4.3.1 Assigned To: wez New Comment: Continuing from the above post I sent 5 minutes ago this link causes php.exe to crash too in 4.3.2 RC 1: http://registration.ft.com/registration/sub/manageYourAccount.jsp Previous Comments: ------------------------------------------------------------------------ [2003-04-17 23:55:39] jim at bluedojo dot com This code produces bug (memory leak?) in 4.3.2 RC 1 (Please excuse the porn link): <? $url = "http://www.free-adult-anime-porn-cartoons.com/robots.txt"; if ($fd = @fopen($url,"r")) echo "Success"; else echo "Failure"; fclose($fd); ?> ------------------------------------------------------------------------ [2003-03-04 10:21:08] iliaa@php.net This bug has been fixed in CVS. In case this was a PHP problem, snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites in short time. Thank you for the report, and for helping us make PHP better. ------------------------------------------------------------------------ [2003-03-04 08:34:18] iliaa@php.net 1 & 2 seems to work fine in latest CVS. #3 is a curios bugger, since it causes an unterminated loop due to what appears to the circular redirect against PHP has no protection. ------------------------------------------------------------------------ [2003-03-03 18:46:30] jim at bluedojo dot com Hello wez, and thanks for the speedy updates on fopen(). I've found some more types of URLS that causes an error using fopen(). I'm using Apache 1.3 and PHP 4.3.x (I used the latest CVS version.) They are listed below. 1.) If it redirects from http:// to https:// it will crash Apache connection. Example Link: http://registration.ft.com/registration/sub/manageYourAccount.jsp 2.) If fopen() loads an unauthorized page -- HTTP Error 403 (Forbidden) it crashes Apache connection. Example Link: http://www.fc-gabarron.es/en 3.) And I'm not sure why this is causing an error: Example Link: http://www.sportingnews.com/RealMedia/ads/click_lx.ads/www.sportingnews.com/soccer/articles/20030302/460373.html/1065908018/Right3/default/empty.gif/34313165376634343365363238633430 I'm not to familiar with programming with sockets and HTTP protocol, but is there a way to catch all the errors and just simply return false if the connection doesn't open? Just place the link in this code to see it happen: <? $url = "(url goes here)"; if ($fd = @fopen($url,"r")) echo "Success"; else echo "Failure"; fclose($fd); ?> ------------------------------------------------------------------------ [2003-03-03 03:22:03] wez@php.net We are not fixing bugs in 4.2.x releases any longer; 4.3.x is the current stable branch, PHP 5 is the current development version. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/22508 -- Edit this bug report at http://bugs.php.net/?id=22508&edit=1

« previous php.bugs (#37837) next »