Bug #62852 [Com]: Unserialize Invalid Date causes crash

From: Date: Thu, 23 Jan 2014 12:13:18 +0000
Subject: Bug #62852 [Com]: Unserialize Invalid Date causes crash
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-183969@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62852&edit=1 ID: 62852 Comment by: mail at ericreiche dot net Reported by: kasper at webmasteren dot eu Summary: Unserialize Invalid Date causes crash Status: Closed Type: Bug Package: Reproducible crash Operating System: windows, linux PHP Version: Irrelevant Assigned To: laruence Block user comment: N Private report: N New Comment: Forgot to mention, version is 5.4.21-1~dotdeb.1 Previous Comments: ------------------------------------------------------------------------ [2014-01-23 12:12:38] mail at ericreiche dot net I'm also still getting this with empty DateTime object in session data O:8:"DateTime":0:{}. ------------------------------------------------------------------------ [2013-11-17 09:31:39] laruence@php.net Automatic comment on behalf of ab Revision: http://git.php.net/?p=php-src.git;a=commit;h=f8b91d9acff10ede7bd3f2bc631794a3abef8ff7 Log: Fixed bug #62852 Unserialize Invalid Date crash ------------------------------------------------------------------------ [2013-11-05 02:59:59] mkwan at corp dot oodle dot com According to the documentation, if "the passed string is not unserializeable, FALSE is returned and E_NOTICE is issued." http://php.net/manual/en/function.unserialize.php Why is it that if the string happens to looks like a DateTime, instead an unrecoverable E_ERROR is issued? ------------------------------------------------------------------------ [2013-04-19 20:42:52] webmaster at thedigitalorchard dot ca My [ugly] workaround for this problem is to manually replace instances of serialized DateTime objects with a fake, non-existent class name, which avoids this crash. $str = 'O:8:"DateTime":0:{}'; $str = str_replace('O:8:"DateTime"', 'O:12:"PHP_DateTime"', $str); Of course, if the serialized data needed to be recovered, an alternate approach would be needed. In my own case, I want to be discarding this object. I'm hoping this issue that ran into is an unforeseen issue with this latest bug fix, and a proper fix can be made in a future update. I don't like adding in workarounds. :-) ------------------------------------------------------------------------ [2013-04-19 20:28:26] webmaster at thedigitalorchard dot ca I'm getting an error since this bug was "fixed". In one of my databases, a DateTime object was inadvertently serialized as a child object. Now, with this bug fix, I'm getting the following error. The serialized object is represented by this short string: O:8:"DateTime":0:{} Running that through unserialize presents this error: "Invalid serialization data for DateTime object" I'm unable to catch this error and handle it gracefully (ie. ignoring this object unserialization entirely). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=62852 -- Edit this bug report at https://bugs.php.net/bug.php?id=62852&edit=1

« previous php.bugs (#183969) next »