Bug #69111 [Csd]: Crash in SessionHandler::read()

From: Date: Fri, 15 Jan 2016 07:29:03 +0000
Subject: Bug #69111 [Csd]: Crash in SessionHandler::read()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198669@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69111&edit=1 ID: 69111 Updated by: yohgaki@php.net Reported by: nikic@php.net Summary: Crash in SessionHandler::read() Status: Closed Type: Bug Package: Session related PHP Version: 5.5.22 Assigned To: yohgaki Block user comment: N Private report: N New Comment: Used PS(session_status) to disable this kind of abuse. Fixed from PHP 5.6. Previous Comments: ------------------------------------------------------------------------ [2016-01-15 07:27:32] yohgaki@php.net Automatic comment on behalf of yohgaki Revision: http://git.php.net/?p=php-src.git;a=commit;h=bfb9307b2d679a91e138fd876880470ece60942b Log: Fixed bug #69111 (Crash in SessionHandler::read()). Made session save handler abuse much harder than before. ------------------------------------------------------------------------ [2015-04-24 06:41:09] yohgaki@php.net I made a PoC patch for this. https://github.com/php/php-src/pull/1248 It's not too complicated, but I would rather remove use of previously defined save handler functions as SessionHandler base class. It just makes things more complicated than needed already. I just don't think we should add more complication to it. ------------------------------------------------------------------------ [2015-02-23 21:32:51] yohgaki@php.net Rather than initializing data by save handler API. I may ask all save handler developers to call session module API to check the session state. I'll fix this by using above method. Comments are appreciated. ------------------------------------------------------------------------ [2015-02-23 21:25:53] yohgaki@php.net Since session_start() isn't called, data->lastkey isn't initialized in this case. Session save handler is not supposed be called by user script, but it seems I should initialize session handler data by session_save_handler(). This requires additional save handler API for save handler data initialization. In mean time, I can invade session module's save handlers (files, mm) without adding new save handler API, but 3rd party modules may crash like this. ------------------------------------------------------------------------ [2015-02-23 20:38:20] nikic@php.net Credit to http://www.reddit.com/user/Nicoon for finding this issue :) ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69111 -- Edit this bug report at https://bugs.php.net/bug.php?id=69111&edit=1

« previous php.bugs (#198669) next »