Bug #72171 [Com]: unserialize() throws a Fatal Error on inaccessible parent classes

From: Date: Mon, 09 May 2016 11:49:44 +0000
Subject: Bug #72171 [Com]: unserialize() throws a Fatal Error on inaccessible parent classes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200951@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72171&edit=1 ID: 72171 Comment by: inefedor at gmail dot com Reported by: php at maisqi dot com Summary: unserialize() throws a Fatal Error on inaccessible parent classes Status: Not a bug Type: Bug Package: Scripting Engine problem Operating System: Windows, Linux PHP Version: 7.0.6 Block user comment: N Private report: N New Comment: Serialized data was never intended to be trusted if it comes from user, this is a mistake to trust user input. For more information see https://www.owasp.org/index.php/Deserialization_of_untrusted_data Previous Comments: ------------------------------------------------------------------------ [2016-05-06 14:43:59] php at maisqi dot com Maybe it's as intended but it's not documented that way -- the docs don't event mention the word «fatal». And even if it were documented, the fact is that anything can happen when we're unserializing. I'd say that all programmers expect unserialize() to either success or fail, not to abort the whole script -- it's a Fatal Error not an Exception (the latter would be acceptable). nickic, can you please make a feature request out of this? At a minimum, there's a security flaw here (it's easy to sabotage a script if we can control the data that it tries to unserialize). ------------------------------------------------------------------------ [2016-05-06 13:32:29] nikic@php.net The behavior is as intended. What you are seeing is an error generated during execution of autoloaded code -- that this error happens to be caused by an undefined class is only incidental. The autoloader might as well cause some other fatal error, throw an exception, cause an exit etc. It is not the job of the unserialize() function to deal with these failures (nor can it, in the general case). ------------------------------------------------------------------------ [2016-05-06 11:48:12] php at maisqi dot com Description: ------------ When unserialize() finds a non-defined class it tries to autload it; but if that succeeds, but that class' base class is not "autoloadable", a Fatal Error is thrown. This makes the unserialize() function totally unpredictable, because we should get a couple of references to __PHP_Incomplete_Class but may just as well get the script aborted. Test script: --------------- <?php // file: "test.php" spl_autoload_register(function($className) {}); spl_autoload_register(function($className) { require_once 'ExistingClass.php'; }); $code = 'O:13:"ExistingClass":0:{}'; $o = unserialize($code); print_r($o); // file ends <?php // file: "ExistingClass.php" class ExistingClass extends NonExistingClass {} // file ends Expected result: ---------------- unserialize() should return a __PHP_Incomplete_Class object. Actual result: -------------- It throws a Fatal Error. This happens in PHP 7.0.6 x64 running on Windows 8 and in PHP 5.5.33 running on Linux CentOS. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72171&edit=1

« previous php.bugs (#200951) next »