Bug #73529 [NEW]: session_decode() silently fails on wrong input

From: Date: Tue, 15 Nov 2016 14:55:34 +0000
Subject: Bug #73529 [NEW]: session_decode() silently fails on wrong input
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-205384@lists.php.net to get a copy of this message
From: love at sickpeople dot se Operating system: PHP version: 7.1.0RC6 Package: Session related Bug Type: Bug Bug description:session_decode() silently fails on wrong input Description: ------------ The session_decode() returns true on most invalid values. Eg NULL, ints, strings in wrong format and empty strings. The docs state "Returns TRUE on success or FALSE on failure." and invalid input should be considered an error. .. An important aspect of this is passing data serialized with another method than the current "session.serialize_handler". These should be considered an error as well. I think this is implied by the docs: "By default, the unserialization method used is internal to PHP, and is not the same as unserialize(). The serialization method can be set using session.serialize_handler." The following two test scripts shows that setting A as serialize handler and passing input serialized with B leads to a silent error. The $_SESSION is not populated but true is returned. Eg /* Test 1 */ $data = array ('foo' => 'bar'); ini_set ('session.serialize_handler', 'php'); session_start (); var_dump (session_decode (serialize ($data))); var_dump ($_SESSION); /* Test 2 */ ini_set ('session.serialize_handler', 'php_serialize'); session_start (); var_dump (session_decode ('foo|s:3:"bar";')); var_dump ($_SESSION); Test script: --------------- ini_set ('session.serialize_handler', 'php'); session_start (); var_dump (session_decode ("foo")); Expected result: ---------------- session_decode() to return false. Actual result: -------------- session_decode() returns true. -- Edit bug report at https://bugs.php.net/bug.php?id=73529&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73529&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73529&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73529&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73529&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73529&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73529&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73529&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73529&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73529&r=support Expected behavior: https://bugs.php.net/fix.php?id=73529&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73529&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73529&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73529&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73529&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73529&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73529&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73529&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73529&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73529&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73529&r=mysqlcfg

« previous php.bugs (#205384) next »