Bug #72178 [Asn->Nab]: unserialize regression in 5.6.21 and 7.0.6

From: Date: Tue, 10 May 2016 16:28:26 +0000
Subject: Bug #72178 [Asn->Nab]: unserialize regression in 5.6.21 and 7.0.6
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200996@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72178&edit=1

 ID:                 72178
 Updated by:         ab@php.net
 Reported by:        bc at benjamin-cremer dot de
 Summary:            unserialize regression in 5.6.21 and 7.0.6
-Status:             Assigned
+Status:             Not a bug
 Type:               Bug
 Package:            *General Issues
 PHP Version:        7.0.6
 Assigned To:        laruence
 Block user comment: N
 Private report:     N

 New Comment:

Hi, thanks for the report. It is a certain BC breach, yes. However the string reported is not
something that serialize() would produce. The related crash bugfix clearly outweighs the fact, that
some invalid data can't be parsed anymore. Thus, not a bug.

Thanks.


Previous Comments:
------------------------------------------------------------------------
[2016-05-10 07:27:30] sjon at hortensius dot net

I agree with laruence, this is not a bug. The offending code should perform $value =
serialize("basic"); dynamically instead of hardcoding its output.

------------------------------------------------------------------------
[2016-05-10 05:45:27] bc at benjamin-cremer dot de

In our case the faulty serialized strings were generated by hand and were used as fixtures, see: https://github.com/shopware/shopware/blob/5.1/_sql/migrations/414-add-product-box-layout.php#L23

We fixed the faulty fixtures in the meantime but this bug affected quite a few customers.

------------------------------------------------------------------------
[2016-05-10 05:25:15] laruence@php.net

the problem here is, how such a serialized string was generated?

every bug fix has side affect.

------------------------------------------------------------------------
[2016-05-10 01:23:03] yohgaki@php.net

https://3v4l.org/qTJ8g

Offending patch is 
http://git.php.net/?p=php-src.git;a=patch;h=6f241f5fad3a26810c96d5b634bfbceaeac10176
for 
https://bugs.php.net/bug.php?id=71840

Laruence, could you take a look?

------------------------------------------------------------------------
[2016-05-09 14:32:57] bc at benjamin-cremer dot de

Relates to: https://bugs.php.net/bug.php?id=71840

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=72178


--
Edit this bug report at https://bugs.php.net/bug.php?id=72178&edit=1


Thread (8 messages)

« previous php.bugs (#200996) next »