Bug #54556 [Com]: array access to empty var does not trigger a notice

From: Date: Thu, 06 Oct 2016 15:29:16 +0000
Subject: Bug #54556 [Com]: array access to empty var does not trigger a notice
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204513@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=54556&edit=1

 ID:                 54556
 Comment by:         bburnichon at gmail dot com
 Reported by:        kal dot el dot ias at gmx dot net
 Summary:            array access to empty var does not trigger a notice
 Status:             Verified
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Ubuntu 10.04.2 LTS
 PHP Version:        trunk-SVN-2011-04-18 (snap)
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

Bug is present for a really long time now.

https://3v4l.org/RUaHX

present in all versions since php 4!
Please fix this, some bad coding can lead to security vulnerabilities.


Previous Comments:
------------------------------------------------------------------------
[2015-06-08 20:50:55] cmb@php.net

Related To: Bug #62769

------------------------------------------------------------------------
[2015-06-08 20:17:35] cmb@php.net

Related To: Bug #54155

------------------------------------------------------------------------
[2015-02-11 18:39:00] kevin dot sours at internetbrands dot com

There has been a patch for this for 4 years?  Any plans to land that in a release?

------------------------------------------------------------------------
[2014-10-07 13:34:12] mathiasgrimm at gmail dot com

I had the same a few days ago.
This behaviour occurs since php 4. I have never noticed that before.

https://bugs.php.net/bug.php?id=68110

------------------------------------------------------------------------
[2013-02-12 16:45:06] gtisza at gmail dot com

The same happens with every non-string scalar value, not just null:

<?php
error_reporting(E_ALL|E_STRICT);
$arr = false;
var_dump($arr['foo']['bar']['baz']); // NULL
?>

This is a major problem as lots of data access functions return null or false if the key is not
found (memcached for example, or may active record libraries), so this bug can easily lead to
unexpected behavior. In unfortunate cases (e.g. trying to load a usergroup blacklist from database)
it might even lead to authentication bypass vulnerabilities and other severe security issues.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=54556


--
Edit this bug report at https://bugs.php.net/bug.php?id=54556&edit=1


Thread (18 messages)

« previous php.bugs (#204513) next »