PHP 4.0 Bug #7565 Updated: upload_max_filesize doesn't work correctly

From: Date: Mon, 18 Dec 2000 16:36:01 +0000
Subject: PHP 4.0 Bug #7565 Updated: upload_max_filesize doesn't work correctly
Groups: php.dev 
Request: Send a blank email to php-dev+get-41785@lists.php.net to get a copy of this message
ID: 7565 Updated by: sniper Reported By: dwakelin@madge.com Old-Status: Open Status: Closed Bug Type: *General Issues Assigned To: Comments: Change it to 2M instead. And use PHP 4.0.3pl1 instead.. --Jani Previous Comments: --------------------------------------------------------------------------- [2000-11-01 06:10:42] dwakelin@madge.com If I set upload_max_filesize=20000000 (in php.ini) and I try to upload a 80 Meg file I do get an error but only after the whole 80 Meg has been loaded into the httpd process (not into a temporary file but into the address space of the Apache server). The system I'm running PHP on only has 32 Meg of memory so an 80 Meg process does it no good at all. I've also tried memory_limit=20000000 (in php.ini) but that doesn't catch the problem. This is with php 4.0.1pl2 (and 3.0.12) running on RedHat Linux 6.1 and Apache 1.3.12 I think the problem lies in "sapi_read_standard_form_data" from mainSAPI.c. The function loops around until it has loaded the entire data into memory before passing it onto the rfc1867 code to reject it with "Max file size of 20000000 bytes exceeded - file [uploadFile]". This behaviour makes my server susceptible to a denial of service attack just by uploading a 140 Meg file the system runs out of memory and swap space and slowly grinds to a halt. --------------------------------------------------------------------------- Full Bug description available at: http://bugs.php.net/?id=7565

« previous php.dev (#41785) next »