|  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Bug #52830 PHP hangs on various setups when trying to read from a corrupted ZIP file
Submitted: 2010-09-13 21:47 UTC Modified: 2010-09-14 14:47 UTC
Avg. Score:5.0 ± 0.0
Reproduced:0 of 0 (0.0%)
From: johannes_schultz at gmx dot de Assigned:
Status: Not a bug Package: Zip Related
PHP Version: Irrelevant OS: Windows, Debian
Private report: No CVE-ID: None
 [2010-09-13 21:47 UTC] johannes_schultz at gmx dot de
I have a broken ZIP file which makes PHP hang on various setups on both Windows and Linux (Debian):
If the CHECKCONS flag is involved, it hangs already when opening the archive, else it will hang when trying to extract the file.

Test script:
$zipRead = new ZipArchive;
$res = $zipRead->open("", ZipArchive::CHECKCONS); // this will hang PHP

Expected result:
Returning an error

Actual result:
PHP hangs


Add a Patch

Pull Requests

Add a Pull Request


AllCommentsChangesGit/SVN commitsRelated reports
 [2010-09-14 08:12 UTC]
-Status: Open +Status: Feedback
 [2010-09-14 08:12 UTC]
Please try using this snapshot:
For Windows:

This sounds like bug #44382, which was fixed some time ago, and I can't reproduce it on a current version of PHP.
 [2010-09-14 13:17 UTC] johannes_schultz at gmx dot de
-Status: Feedback +Status: Open
 [2010-09-14 13:17 UTC] johannes_schultz at gmx dot de
Seems to work with the current snapshot, thanks. No I wonder when this fix will be available through the Debian update...
 [2010-09-14 13:21 UTC]
-Status: Open +Status: Feedback
 [2010-09-14 13:21 UTC]
Current snapshot or 5.3.3? It should work with 5.3.3 too. Can you try it as well please?
 [2010-09-14 13:22 UTC] johannes_schultz at gmx dot de
-Status: Feedback +Status: Open
 [2010-09-14 13:22 UTC] johannes_schultz at gmx dot de
I tried 5.3.3, no problems there.
 [2010-09-14 13:23 UTC]
-Status: Open +Status: Bogus
 [2010-09-14 13:23 UTC]
Thanks :)

Not a bug, already fixed > bogus.
 [2010-09-14 13:26 UTC] johannes_schultz at gmx dot de
Is there a way to somehow circumvent this problem on older versions, though? I don't really want to mess around with the server software, even if I can.
 [2010-09-14 13:33 UTC]
You can compile your own zip extension and use it until Debian has updated their package.
 [2010-09-14 14:47 UTC] johannes_schultz at gmx dot de
Ok, so is there a quick way to _just_ build the zip extension? A quick glance at the "configure" help at least doesn't show a quick way to ignore all other stuff to be built...
PHP Copyright © 2001-2020 The PHP Group
All rights reserved.
Last updated: Fri Nov 27 12:01:23 2020 UTC