Bug #69111 [Csd]: Crash in SessionHandler::read()
| From: | yohgaki@php.net | Date: | Fri, 15 Jan 2016 07:29:03 +0000 |
| Subject: | Bug #69111 [Csd]: Crash in SessionHandler::read() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-198669@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69111&edit=1
ID: 69111
Updated by: yohgaki@php.net
Reported by: nikic@php.net
Summary: Crash in SessionHandler::read()
Status: Closed
Type: Bug
Package: Session related
PHP Version: 5.5.22
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Used PS(session_status) to disable this kind of abuse. Fixed from PHP 5.6.
Previous Comments:
------------------------------------------------------------------------
[2016-01-15 07:27:32] yohgaki@php.net
Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=bfb9307b2d679a91e138fd876880470ece60942b
Log: Fixed bug #69111 (Crash in SessionHandler::read()). Made session save handler abuse much harder
than before.
------------------------------------------------------------------------
[2015-04-24 06:41:09] yohgaki@php.net
I made a PoC patch for this.
https://github.com/php/php-src/pull/1248
It's not too complicated, but I would rather remove use of previously defined save handler
functions as SessionHandler base class. It just makes things more complicated than needed already. I
just don't think we should add more complication to it.
------------------------------------------------------------------------
[2015-02-23 21:32:51] yohgaki@php.net
Rather than initializing data by save handler API. I may ask all save handler developers to call
session module API to check the session state.
I'll fix this by using above method.
Comments are appreciated.
------------------------------------------------------------------------
[2015-02-23 21:25:53] yohgaki@php.net
Since session_start() isn't called, data->lastkey isn't initialized in this case.
Session save handler is not supposed be called by user script, but it seems I should initialize
session handler data by session_save_handler().
This requires additional save handler API for save handler data initialization.
In mean time, I can invade session module's save handlers (files, mm) without adding new save
handler API, but 3rd party modules may crash like this.
------------------------------------------------------------------------
[2015-02-23 20:38:20] nikic@php.net
Credit to http://www.reddit.com/user/Nicoon for
finding this issue :)
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69111
--
Edit this bug report at https://bugs.php.net/bug.php?id=69111&edit=1