bug78599-path-info-underflow.phpt 1.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061
  1. --TEST--
  2. FPM: bug78599 - env_path_info underflow - CVE-2019-11043
  3. --SKIPIF--
  4. <?php include "skipif.inc"; ?>
  5. --FILE--
  6. <?php
  7. require_once "tester.inc";
  8. $cfg = <<<EOT
  9. [global]
  10. error_log = {{FILE:LOG}}
  11. [unconfined]
  12. listen = {{ADDR}}
  13. pm = dynamic
  14. pm.max_children = 5
  15. pm.start_servers = 1
  16. pm.min_spare_servers = 1
  17. pm.max_spare_servers = 3
  18. EOT;
  19. $code = <<<EOT
  20. <?php
  21. echo "Test Start\n";
  22. var_dump(\$_SERVER["PATH_INFO"]);
  23. echo "Test End\n";
  24. EOT;
  25. $tester = new FPM\Tester($cfg, $code);
  26. $tester->start();
  27. $tester->expectLogStartNotices();
  28. $uri = $tester->makeSourceFile();
  29. $tester
  30. ->request(
  31. '',
  32. [
  33. 'SCRIPT_FILENAME' => $uri . "/" . str_repeat('A', 35),
  34. 'PATH_INFO' => '',
  35. 'HTTP_HUI' => str_repeat('PTEST', 1000),
  36. ],
  37. $uri
  38. )
  39. ->expectBody(
  40. [
  41. 'Test Start',
  42. 'string(0) ""',
  43. 'Test End'
  44. ]
  45. );
  46. $tester->terminate();
  47. $tester->close();
  48. ?>
  49. Done
  50. --EXPECT--
  51. Done
  52. --CLEAN--
  53. <?php
  54. require_once "tester.inc";
  55. FPM\Tester::clean();
  56. ?>