Bug #66827 [Asn]: session_start generates PHP Notice if session cookie contains array
| From: | yohgaki@php.net | Date: | Fri, 18 Jul 2014 05:32:34 +0000 |
| Subject: | Bug #66827 [Asn]: session_start generates PHP Notice if session cookie contains array | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186715@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66827&edit=1
ID: 66827
Updated by: yohgaki@php.net
Reported by: spam at krol dot me
Summary: session_start generates PHP Notice if session cookie
contains array
Status: Assigned
Type: Bug
Package: Session related
Operating System: osx
PHP Version: 5.5.9
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
I'm going to commit to remove type mismatch E_NOTICE errors. However, the patch will not try to
remove offensive cookies, probably.
Depending on cookie precedence, session module's cookie will not be effective. i.e. Users may
not get valid session, thus users cannot login/etc.
These malformed cookie are set by JavaScript injections. Developer must fix vulnerability, then
remove offensive cookie by their own or ask users to delete cookies.
Previous Comments:
------------------------------------------------------------------------
[2014-07-17 06:17:00] yohgaki@php.net
Not only $_COOKIE, but also $_GET/$_POST could be used to raise errors.
OS does not matter and affects all versions.
------------------------------------------------------------------------
[2014-03-06 13:04:15] patryk dot kozlowski at toxic-software dot pl
Many developers consider sessions as internal PHP mechanism and don't bother to check for
session id malformation. If you want to keep this 'call session_start & play'
standard, this bug definitely need a fix (as spam mentioned: is_string will do the job).
For now you can trigger PHP_Notice error on many PHP websites (including ZF based) by executing
one-line JavaScript code.
------------------------------------------------------------------------
[2014-03-06 12:36:17] narf at devilix dot net
Hmm, I guess you do have a point in that, although I'm not sure how $_COOKIE itself is
populated.
------------------------------------------------------------------------
[2014-03-06 12:28:21] spam at krol dot me
If malformed cookie can cause application error i would consider this as a bug.
Maybe at least is_string check before unserialize?
If not I think this can be closed.
------------------------------------------------------------------------
[2014-03-06 12:17:44] narf at devilix dot net
That's completely natural, since the cookie value is unserialized by session_start() and you
can't unserialize an array(). I wouldn't consider it a bug.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66827
--
Edit this bug report at https://bugs.php.net/bug.php?id=66827&edit=1