Bug #62789 [Opn->Csd]: Autoloaders are invoked with invalid class names

From: Date: Tue, 08 Sep 2015 14:02:39 +0000
Subject: Bug #62789 [Opn->Csd]: Autoloaders are invoked with invalid class names
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195876@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62789&edit=1 ID: 62789 Updated by: cmb@php.net Reported by: drak at zikula dot org Summary: Autoloaders are invoked with invalid class names -Status: Open +Status: Closed Type: Bug Package: SPL related PHP Version: 5.3.15 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Indeed, this issue has been resolved as of PHP 5.4.24[1] and PHP 5.5.8: | Added validation of class names in the autoload process. [1] <http://www.php.net/ChangeLog-5.php#5.4.24> Previous Comments: ------------------------------------------------------------------------ [2014-05-30 05:00:40] php at danielfriesen dot name Looks like this bug was fixed at some point in 5.4. ------------------------------------------------------------------------ [2013-02-05 17:39:00] levim@php.net I suggest not creating a class from arbitrary strings you pick up from the internet . . . ------------------------------------------------------------------------ [2012-08-10 07:27:50] victor dot berchet at sensiolabs dot com As indicated in the blog post linked in the issue report, a few functions are affected (ie they can trigger the autoload function with an invalid class name): - class_exists() - interface_exists() - class_parents() - class_implements() - is_subclass_of() ------------------------------------------------------------------------ [2012-08-09 20:04:23] drak at zikula dot org Description: ------------ It is possible to invoke class autoloaders with invalid class names leading to potential security issues. Classes can contain alphaumeric, underscore and backslash characters. However, code like: $foo = new $class where $class might contain any arbitrary string will cause the autoloader stack to be called even if the $class variable contained invalid characters for a class name. This could lead to various file inclusion issues as detailed in http://drak3.devmx.de/blog/2012/08/08/autoloaded-remote-file-inclusion/ However, it is not reasonable for classloaders to validate the class name passed to it via PHP for valid classname characters. Doing so would be an incredible burden on performance ever increasing with the size of the autoloader stack. I suggest that PHP validate the characters of the class before deciding to call the autoloader stack or not. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=62789&edit=1

« previous php.bugs (#195876) next »