Bug #72785 [Opn->Csd]: allowed_classes only applies to outermost unserialize()
| From: | stas@php.net | Date: | Tue, 06 Sep 2016 02:58:10 +0000 |
| Subject: | Bug #72785 [Opn->Csd]: allowed_classes only applies to outermost unserialize() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-203822@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72785&edit=1
ID: 72785
Updated by: stas@php.net
Reported by: nikic@php.net
Summary: allowed_classes only applies to outermost
unserialize()
-Status: Open
+Status: Closed
Type: Bug
Package: Scripting Engine problem
PHP Version: 7.0.9
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=747d21cfd2a7414b8d5ace203524f61eab2b8323
Log: Fix bug #72785 - allowed_classes only applies to outermost unserialize()
Previous Comments:
------------------------------------------------------------------------
[2016-09-06 01:23:43] stas@php.net
The fix still doesn't seem to be complete, since we don't pass it when we parse keys.
Maybe we should ban objects completely when we are parsing keys.
------------------------------------------------------------------------
[2016-08-15 21:49:03] nikic@php.net
Looks reasonable. Notes:
* The new type check needs a PHP_VAR_UNSERIALIZE_DESTROY.
* As this is PHP 7.1-only anyway, maybe we could drop php_var_unserialize_ex and make the
unserialize_data the canonical source of truth about allowed classes?
Variant with these changes: https://gist.github.com/nikic/c7941621d3a083f84d05d46c1cef35bd
------------------------------------------------------------------------
[2016-08-14 01:22:36] stas@php.net
Proposed fix https://gist.github.com/360b34c65bcb11f917bbef4ba29acfd3
It requires slight BC break, so I am not sure but do not see better alternative.
------------------------------------------------------------------------
[2016-08-13 20:32:08] stas@php.net
BTW your example code has a bug - allowed_classes value should be an array. We probably need to add
notice or something on this...
------------------------------------------------------------------------
[2016-08-10 06:19:59] stas@php.net
Yeah that's a problem for nested unserialize's that use internal container classes...
I'm not sure it's possible to fix it without adding arguments or globals (i.e. BC break).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72785
--
Edit this bug report at https://bugs.php.net/bug.php?id=72785&edit=1