Req->Bug #44031 [Opn]: vprint treats private object elements as array elements

From: Date: Sun, 21 Feb 2016 12:40:56 +0000
Subject: Req->Bug #44031 [Opn]: vprint treats private object elements as array elements
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199370@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=44031&edit=1 ID: 44031 Updated by: nikic@php.net Reported by: m dot beyer5 at gmx dot de Summary: vprint treats private object elements as array elements Status: Open -Type: Feature/Change Request +Type: Bug Package: *General Issues Operating System: Debian Linux PHP Version: 5.2.5 Block user comment: N Private report: N New Comment: This is an artifact of vprintf not using zpp properly, it does manual argument handling instead and does it incorrectly. Previous Comments: ------------------------------------------------------------------------ [2015-05-17 18:28:15] cmb@php.net The behavior is not particularly related to vprinf(), but that is rather how casting objects to arrays work in PHP, see <http://3v4l.org/3R6QT>. ------------------------------------------------------------------------ [2008-02-03 12:50:12] m dot beyer5 at gmx dot de Description: ------------ If an object is supplied instead of an array, v(s)printf takes the internal object elements as elements despite of its visibility. This is not only quite annoying but could be a security issue as well. Reproduce code: --------------- class foo { private $x = 1; private $y = 2; } $array = new foo; vprintf('%s < %s',$array); Expected result: ---------------- An E_WARNING should be triggered. Alternatively, vprintf could take an object instantiating or extending ArrayObject and behave according to the objects functions. Actual result: -------------- vprintf prints: 1 < 2 ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=44031&edit=1

« previous php.bugs (#199370) next »