Bug #62852 [Com]: Unserialize Invalid Date causes crash
| From: | mail at ericreiche dot net | Date: | Thu, 23 Jan 2014 12:13:18 +0000 |
| Subject: | Bug #62852 [Com]: Unserialize Invalid Date causes crash | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-183969@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62852&edit=1
ID: 62852
Comment by: mail at ericreiche dot net
Reported by: kasper at webmasteren dot eu
Summary: Unserialize Invalid Date causes crash
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: windows, linux
PHP Version: Irrelevant
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
Forgot to mention, version is 5.4.21-1~dotdeb.1
Previous Comments:
------------------------------------------------------------------------
[2014-01-23 12:12:38] mail at ericreiche dot net
I'm also still getting this with empty DateTime object in session data
O:8:"DateTime":0:{}.
------------------------------------------------------------------------
[2013-11-17 09:31:39] laruence@php.net
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=f8b91d9acff10ede7bd3f2bc631794a3abef8ff7
Log: Fixed bug #62852 Unserialize Invalid Date crash
------------------------------------------------------------------------
[2013-11-05 02:59:59] mkwan at corp dot oodle dot com
According to the documentation, if "the passed string is not unserializeable, FALSE is returned
and E_NOTICE is issued."
http://php.net/manual/en/function.unserialize.php
Why is it that if the string happens to looks like a DateTime, instead an unrecoverable E_ERROR is
issued?
------------------------------------------------------------------------
[2013-04-19 20:42:52] webmaster at thedigitalorchard dot ca
My [ugly] workaround for this problem is to manually replace instances of
serialized DateTime objects with a fake, non-existent class name, which avoids
this crash.
$str = 'O:8:"DateTime":0:{}';
$str = str_replace('O:8:"DateTime"', 'O:12:"PHP_DateTime"',
$str);
Of course, if the serialized data needed to be recovered, an alternate approach
would be needed. In my own case, I want to be discarding this object. I'm hoping
this issue that ran into is an unforeseen issue with this latest bug fix, and a
proper fix can be made in a future update. I don't like adding in workarounds. :-)
------------------------------------------------------------------------
[2013-04-19 20:28:26] webmaster at thedigitalorchard dot ca
I'm getting an error since this bug was "fixed". In one of my databases, a
DateTime object was inadvertently serialized as a child object. Now, with this bug
fix, I'm getting the following error.
The serialized object is represented by this short string:
O:8:"DateTime":0:{}
Running that through unserialize presents this error:
"Invalid serialization data for DateTime object"
I'm unable to catch this error and handle it gracefully (ie. ignoring this object
unserialization entirely).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62852
--
Edit this bug report at https://bugs.php.net/bug.php?id=62852&edit=1