Bug #73394 [NEW]: php_session_initialize doesn't verify s_read return value

From: Date: Wed, 26 Oct 2016 16:13:09 +0000
Subject: Bug #73394 [NEW]: php_session_initialize doesn't verify s_read return value
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205028@lists.php.net to get a copy of this message
From:             martijn at openbsd dot org
Operating system: irrelevant
PHP version:      7.0.12
Package:          Session related
Bug Type:         Bug
Bug description:php_session_initialize doesn't verify s_read return value

Description:
------------
When a read from the session backend fails it still initializes the
session without data. This causes problems during either the closing of
the session or the php_session_decode (depending on the serializer) with
writing an empty session or destroying the session data respectively.

I choose E_ERROR to be in line with s_open and s_create_id function
checks, but it can easily changed into E_WARNING to be more in line with
the original comment and would cause a return FALSE, because
PS(session_status) is not php_session_active.

I haven't looked into other versions, but I guess this applies to other
versions as well.

Test script:
---------------
Originally found with
https://github.com/php-memcached-dev/php-memcached/
as a session
backend.
The script below can be tested by setting up memcached and doing a
"add memc.sess.lock.<session_id> 0 0 1"  on a telnet session to
memcached (make sure that memcached.session_locking is set, which it is
by default).
The request will first hang and at the end reset the session content in
memcached.

<?php
ini_set('session.save_handler', 'memcached');
ini_set('session.save_path', "127.0.0.01:11211");

session_start();
var_dump($_SESSION, session_id());
$_SESSION["a"] = "b";



-- 
Edit bug report at https://bugs.php.net/bug.php?id=73394&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=73394&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=73394&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=73394&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=73394&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=73394&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=73394&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=73394&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=73394&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=73394&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=73394&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=73394&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=73394&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=73394&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73394&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=73394&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=73394&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=73394&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73394&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=73394&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=73394&r=mysqlcfg



Thread (5 messages)

« previous php.bugs (#205028) next »