Bug #67363 [Opn]: Unserialize corrupts data

From: Date: Fri, 30 May 2014 16:55:42 +0000
Subject: Bug #67363 [Opn]: Unserialize corrupts data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185989@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67363&edit=1 ID: 67363 User updated by: mg at artigo dot pl Reported by: mg at artigo dot pl Summary: Unserialize corrupts data Status: Open Type: Bug Package: Variables related Operating System: Irrelavant PHP Version: Irrelevant Block user comment: N Private report: N New Comment: It seems that serialize function has something to do with it, it gives different outputs: Case1, output of: serialize(unserialize(serialize($data))); https://dl.dropboxusercontent.com/u/11435743/php/serialize_unserialize_serialize.txt Case 2, output of: serialize($data) https://dl.dropboxusercontent.com/u/11435743/php/serialize.txt I attach this example, because data corruption does seem to occur in Case 1. It seems only to occur in Case 2. Previous Comments: ------------------------------------------------------------------------ [2014-05-30 15:26:26] mg at artigo dot pl Description: ------------ Unserialize method of PHP corrupts random values inside serialized objects. Corrupted value may be a string (in this case it is clearly visible on the website). We have encountered this issue on every PHP version from 5.3 to 5.5 and multiple environments (linux, windows). PHP 5.2 was free from this bug (version switching proved it). The corruption occurs only on some value combinations, for example after we change one of the string values the corruption does not appear, when we changed it back: the corruption occurs again. The type of object does not matter, it often happens for stdClass. Please check an example object, which was used in Test script: https://dl.dropboxusercontent.com/u/11435743/php/load.txt Please compare it with the object which is an output of unserialize function. https://dl.dropboxusercontent.com/u/11435743/php/load_corrupt.txt Clearly one of the values has changed: Instead of "Make-up & Styling", value is now: "Make-up ' Sty Please note that pasting of the corrupt string works only until letter "y", please check the load_corrupt.txt file to see the full string. The corruption may have a various form, it can be an additional letter, changed letter, for example: "Stylid" instead of "Styling". Test script: --------------- file_put_contents('load.txt', $data); // correct object file_put_contents('load_corrupt.txt', serialize(unserialize($data))); // one of the value was changed by unserialize, we serialize it back to save it to file Expected result: ---------------- "make-up-styling";s:4:"name";s:17:"Make-up & Styling" Actual result: -------------- s:15:"make-up-styling";s:4:"name";s:17:"Make-up ' Sty ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67363&edit=1

« previous php.bugs (#185989) next »