Bug #45573 [ReO->Nab]: unserialize does not work if a linebreak is inside the input string

From: Date: Tue, 26 Jul 2016 23:03:34 +0000
Subject: Bug #45573 [ReO->Nab]: unserialize does not work if a linebreak is inside the input string
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202619@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=45573&edit=1 ID: 45573 Updated by: nikic@php.net Reported by: t_mueller_stolzenhain at yahoo dot de Summary: unserialize does not work if a linebreak is inside the input string -Status: Re-Opened +Status: Not a bug Type: Bug Package: Strings related Operating System: any PHP Version: any Block user comment: N Private report: N New Comment: Closing here, as this is working as intended. The serialized string has been corrupted and consequently unserialize fails. Serialized data is binary data, it can't be treated as "text". Previous Comments: ------------------------------------------------------------------------ [2015-07-01 11:55:40] cmb@php.net This is not a general bug. unserialize() fails due to the wrong string length; s:11 has to be changed to s:12 when the LF is replaced by CRLF, see <http://3v4l.org/u03Ek>. The PEAR issue still may be an issue or not. ------------------------------------------------------------------------ [2015-07-01 05:39:05] yohgaki@php.net @josh Because this is marked as Not a Bug. I re-opened this. ------------------------------------------------------------------------ [2015-06-30 14:49:47] josh at josheaton dot org I'm wondering why this issue never got any attention even with a reduced test case that reproduced the issue? I recently ran into this issue with a WordPress site and found this bug. WordPress ticket: https://core.trac.wordpress.org/ticket/23275#comment:7 netweb was kind enough to provide a link that tests the issue in many different PHP versions, and it appears to break in all of them. Any windows line endings within a serialized string break when unserialized. http://3v4l.org/X0pFQ Is it possible to reopen this issue? ------------------------------------------------------------------------ [2008-07-25 19:18:45] t_mueller_stolzenhain at yahoo dot de sample to reproduce the error I had: <?php //the original array $a = array( 'a23' => 'abcdefg hij' ); //make it serial $s = serialize($a); //just to see the serial string var_dump($s); //the serialized array $s1 = 'a:1:{s:3:"a23";s:11:"abcdefg hij";}'; //the same with linux line end character $s2 = "a:1:{s:3:\"a23\";s:11:\"abcdefg\12hij\";}"; //the same with windows line end character, same I had in my PEAR files $s3 = "a:1:{s:3:\"a23\";s:11:\"abcdefg\15\12hij\";}"; //turn it back to an array $a1 = unserialize($s1); // ok $a2 = unserialize($s2); // ok $a3 = unserialize($s3); // not ok ?> ------------------------------------------------------------------------ [2008-07-24 23:04:14] jani@php.net As long as there is no preproducing script, there is no problem either. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=45573 -- Edit this bug report at https://bugs.php.net/bug.php?id=45573&edit=1

« previous php.bugs (#202619) next »