Bug #66827 [Asn]: session_start generates PHP Notice if session cookie contains array

From: Date: Fri, 18 Jul 2014 05:32:34 +0000
Subject: Bug #66827 [Asn]: session_start generates PHP Notice if session cookie contains array
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186715@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66827&edit=1 ID: 66827 Updated by: yohgaki@php.net Reported by: spam at krol dot me Summary: session_start generates PHP Notice if session cookie contains array Status: Assigned Type: Bug Package: Session related Operating System: osx PHP Version: 5.5.9 Assigned To: yohgaki Block user comment: N Private report: N New Comment: I'm going to commit to remove type mismatch E_NOTICE errors. However, the patch will not try to remove offensive cookies, probably. Depending on cookie precedence, session module's cookie will not be effective. i.e. Users may not get valid session, thus users cannot login/etc. These malformed cookie are set by JavaScript injections. Developer must fix vulnerability, then remove offensive cookie by their own or ask users to delete cookies. Previous Comments: ------------------------------------------------------------------------ [2014-07-17 06:17:00] yohgaki@php.net Not only $_COOKIE, but also $_GET/$_POST could be used to raise errors. OS does not matter and affects all versions. ------------------------------------------------------------------------ [2014-03-06 13:04:15] patryk dot kozlowski at toxic-software dot pl Many developers consider sessions as internal PHP mechanism and don't bother to check for session id malformation. If you want to keep this 'call session_start & play' standard, this bug definitely need a fix (as spam mentioned: is_string will do the job). For now you can trigger PHP_Notice error on many PHP websites (including ZF based) by executing one-line JavaScript code. ------------------------------------------------------------------------ [2014-03-06 12:36:17] narf at devilix dot net Hmm, I guess you do have a point in that, although I'm not sure how $_COOKIE itself is populated. ------------------------------------------------------------------------ [2014-03-06 12:28:21] spam at krol dot me If malformed cookie can cause application error i would consider this as a bug. Maybe at least is_string check before unserialize? If not I think this can be closed. ------------------------------------------------------------------------ [2014-03-06 12:17:44] narf at devilix dot net That's completely natural, since the cookie value is unserialized by session_start() and you can't unserialize an array(). I wouldn't consider it a bug. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=66827 -- Edit this bug report at https://bugs.php.net/bug.php?id=66827&edit=1

« previous php.bugs (#186715) next »