Bug #66827 [Asn->Csd]: session_start generates PHP Notice if session cookie contains array
| From: | yohgaki@php.net | Date: | Sat, 19 Jul 2014 01:04:50 +0000 |
| Subject: | Bug #66827 [Asn->Csd]: session_start generates PHP Notice if session cookie contains array | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186737@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66827&edit=1
ID: 66827
Updated by: yohgaki@php.net
Reported by: spam at krol dot me
Summary: session_start generates PHP Notice if session cookie
contains array
-Status: Assigned
+Status: Closed
Type: Bug
Package: Session related
Operating System: osx
PHP Version: 5.5.9
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=e946de29d2f337f140780086b0ccefd13e2095ef
Log: Fixed bug #66827 Session raises E_NOTICE when session name variable is array
Previous Comments:
------------------------------------------------------------------------
[2014-07-18 05:32:33] yohgaki@php.net
I'm going to commit to remove type mismatch E_NOTICE errors. However, the patch will not try to
remove offensive cookies, probably.
Depending on cookie precedence, session module's cookie will not be effective. i.e. Users may
not get valid session, thus users cannot login/etc.
These malformed cookie are set by JavaScript injections. Developer must fix vulnerability, then
remove offensive cookie by their own or ask users to delete cookies.
------------------------------------------------------------------------
[2014-07-17 06:17:00] yohgaki@php.net
Not only $_COOKIE, but also $_GET/$_POST could be used to raise errors.
OS does not matter and affects all versions.
------------------------------------------------------------------------
[2014-03-06 13:04:15] patryk dot kozlowski at toxic-software dot pl
Many developers consider sessions as internal PHP mechanism and don't bother to check for
session id malformation. If you want to keep this 'call session_start & play'
standard, this bug definitely need a fix (as spam mentioned: is_string will do the job).
For now you can trigger PHP_Notice error on many PHP websites (including ZF based) by executing
one-line JavaScript code.
------------------------------------------------------------------------
[2014-03-06 12:36:17] narf at devilix dot net
Hmm, I guess you do have a point in that, although I'm not sure how $_COOKIE itself is
populated.
------------------------------------------------------------------------
[2014-03-06 12:28:21] spam at krol dot me
If malformed cookie can cause application error i would consider this as a bug.
Maybe at least is_string check before unserialize?
If not I think this can be closed.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66827
--
Edit this bug report at https://bugs.php.net/bug.php?id=66827&edit=1