Bug #67072 [Csd]: Echoing unserialized "SplFileObject" crash
| From: | tyrael@php.net | Date: | Thu, 19 Jun 2014 23:54:53 +0000 |
| Subject: | Bug #67072 [Csd]: Echoing unserialized "SplFileObject" crash | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186267@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67072&edit=1
ID: 67072
Updated by: tyrael@php.net
Reported by: arteau dot olivier at gmail dot com
Summary: Echoing unserialized "SplFileObject" crash
Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Windows / Linux
PHP Version: 5.5.11
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
The fix for this issue caused some BC breaks in the userland, because some popular libs like
phpunit-mock-objects and doctrine are using handcrafter serialize strings for easy instantiation of
object without calling the constructors.
For that usecase ReflectionClass::newInstanceWithoutConstructor() should be used instead, but that
requires PHP >= 5.4 and also prohibits instantiation of internal classes, or userland classes
extending internal classes.
For instantiation of classes implementing the Serializable interface the "C:" format
should be used instead of the "O:", as it will properly call the unserialize method
defined for that class, but manually building valid strings for that format is a bit harder, see https://bugs.php.net/bug.php?id=67453&edit=1
For the discussion about the Unserialize trick and the constructless instanitation of internal
classes see:
http://www.serverphorums.com/read.php?7,927788
http://www.serverphorums.com/read.php?7,946926
http://www.serverphorums.com/read.php?7,959450
Previous Comments:
------------------------------------------------------------------------
[2014-05-01 14:59:22] tyrael@php.net
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=5328d4289946e260232f3195ba2e0f0eb173d5ef
Log: Fixed bug #67072 Echoing unserialized "SplFileObject" crash
------------------------------------------------------------------------
[2014-04-20 18:39:51] ab@php.net
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=5328d4289946e260232f3195ba2e0f0eb173d5ef
Log: Fixed bug #67072 Echoing unserialized "SplFileObject" crash
------------------------------------------------------------------------
[2014-04-20 18:38:37] ab@php.net
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=5328d4289946e260232f3195ba2e0f0eb173d5ef
Log: Fixed bug #67072 Echoing unserialized "SplFileObject" crash
------------------------------------------------------------------------
[2014-04-17 09:10:23] ab@php.net
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=5328d4289946e260232f3195ba2e0f0eb173d5ef
Log: Fixed bug #67072 Echoing unserialized "SplFileObject" crash
------------------------------------------------------------------------
[2014-04-14 04:22:33] arteau dot olivier at gmail dot com
Description:
------------
Executing the script below crashes PHP.
Some quick debugging on my part seems to point to a NULL dereference bug in the spl related code.
However, since I was debugging from the binary it's hard to tell where exactly in the code it
is.
Test script:
---------------
<?php
echo
unserialize('O:13:"SplFileObject":1:{s:9:"*filename";s:15:"/home/flag/flag";}');
?>
Expected result:
----------------
Since "SplFileObject" aren't serializable, an exception should be thrown or
bool(false) should be returned.
Actual result:
--------------
PHP crash.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67072&edit=1