Bug #72178 [Com]: unserialize regression in 5.6.21 and 7.0.6
| From: | bc at benjamin-cremer dot de | Date: | Tue, 10 May 2016 05:45:31 +0000 |
| Subject: | Bug #72178 [Com]: unserialize regression in 5.6.21 and 7.0.6 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200982@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72178&edit=1
ID: 72178
Comment by: bc at benjamin-cremer dot de
Reported by: bc at benjamin-cremer dot de
Summary: unserialize regression in 5.6.21 and 7.0.6
Status: Assigned
Type: Bug
Package: *General Issues
PHP Version: 7.0.6
Assigned To: laruence
Block user comment: N
Private report: N
New Comment:
In our case the faulty serialized strings were generated by hand and were used as fixtures, see: https://github.com/shopware/shopware/blob/5.1/_sql/migrations/414-add-product-box-layout.php#L23
We fixed the faulty fixtures in the meantime but this bug affected quite a few customers.
Previous Comments:
------------------------------------------------------------------------
[2016-05-10 05:25:15] laruence@php.net
the problem here is, how such a serialized string was generated?
every bug fix has side affect.
------------------------------------------------------------------------
[2016-05-10 01:23:03] yohgaki@php.net
https://3v4l.org/qTJ8g
Offending patch is
http://git.php.net/?p=php-src.git;a=patch;h=6f241f5fad3a26810c96d5b634bfbceaeac10176
for
https://bugs.php.net/bug.php?id=71840
Laruence, could you take a look?
------------------------------------------------------------------------
[2016-05-09 14:32:57] bc at benjamin-cremer dot de
Relates to: https://bugs.php.net/bug.php?id=71840
------------------------------------------------------------------------
[2016-05-09 14:29:48] bc at benjamin-cremer dot de
See: https://3v4l.org/qTJ8g
------------------------------------------------------------------------
[2016-05-09 13:59:03] bc at benjamin-cremer dot de
Description:
------------
When using
unserialize() on a serialized string missing the trailing semicolon a notice
will be triggered and false will be returned.
This is a backwards compatibility break introduced in 5.6.21 and 7.0.6.
Test script:
---------------
var_dump(unserialize('s:4:"test"'));
Expected result:
----------------
string(4) "test"
Actual result:
--------------
PHP Notice: unserialize(): Error at offset 10 of 10 bytes in php shell code on line 1
bool(false)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72178&edit=1