Sec Bug->Req #72091 [Opn]: session data persistence after destroying session

From: Date: Sun, 24 Apr 2016 18:18:25 +0000
Subject: Sec Bug->Req #72091 [Opn]: session data persistence after destroying session
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200751@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72091&edit=1

 ID:                 72091
 Updated by:         stas@php.net
 Reported by:        rprporwal9 at gmail dot com
 Summary:            session data persistence after destroying session
 Status:             Open
-Type:               Security
+Type:               Feature/Change Request
 Package:            Session related
 Operating System:   Ubuntu
 PHP Version:        5.5.34
 Block user comment: N
 Private report:     Y

 New Comment:

Not a security issue. 

Also, documented behavior of session_destroy.


Previous Comments:
------------------------------------------------------------------------
[2016-04-24 05:21:09] rprporwal9 at gmail dot com

Description:
------------
After session initialization we store data in session super global array but after invocation of
session_destroy function which is used to destroy session data in session super global variable
should also be unset simultaneously.

Otherwise there is no meaning of session_destroy if data persists in session super global variable

Also according to documentation of session_destroy function as mentioned in php.net

Destroys all data registered to a session

Hence I suggest that data should not persist after session is destroyed in super global $_SESSION
variable otherwise there is no reliability of session_destroy() function.

Test script:
---------------
session_start();
$_SESSION['xyz']=99;
session_destroy();
print_r($_SESSION);



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72091&edit=1


Thread (1 message)

  • stas@php.net
  • Unknown Message
    • stas@php.net
« previous php.bugs (#200751) next »