Bug #73529 [NEW]: session_decode() silently fails on wrong input
| From: | love at sickpeople dot se | Date: | Tue, 15 Nov 2016 14:55:34 +0000 |
| Subject: | Bug #73529 [NEW]: session_decode() silently fails on wrong input | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-205384@lists.php.net to get a copy of this message | ||
From: love at sickpeople dot se
Operating system:
PHP version: 7.1.0RC6
Package: Session related
Bug Type: Bug
Bug description:session_decode() silently fails on wrong input
Description:
------------
The session_decode() returns true on most invalid values. Eg NULL, ints,
strings in wrong format and empty strings.
The docs state "Returns TRUE on success or FALSE on failure." and
invalid input should be considered an error.
..
An important aspect of this is passing data serialized with another
method than the current "session.serialize_handler". These should be
considered an error as well. I think this is implied by the docs:
"By default, the unserialization method used is internal to PHP, and
is not the same as unserialize(). The serialization method can be set
using session.serialize_handler."
The following two test scripts shows that setting A as serialize handler
and passing input serialized with B leads to a silent error. The
$_SESSION is not populated but true is returned.
Eg
/* Test 1 */
$data = array ('foo' => 'bar');
ini_set ('session.serialize_handler', 'php');
session_start ();
var_dump (session_decode (serialize ($data)));
var_dump ($_SESSION);
/* Test 2 */
ini_set ('session.serialize_handler', 'php_serialize');
session_start ();
var_dump (session_decode ('foo|s:3:"bar";'));
var_dump ($_SESSION);
Test script:
---------------
ini_set ('session.serialize_handler', 'php');
session_start ();
var_dump (session_decode ("foo"));
Expected result:
----------------
session_decode() to return false.
Actual result:
--------------
session_decode() returns true.
--
Edit bug report at https://bugs.php.net/bug.php?id=73529&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73529&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73529&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73529&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73529&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73529&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73529&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73529&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73529&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73529&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73529&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73529&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73529&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73529&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73529&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73529&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73529&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73529&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73529&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73529&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73529&r=mysqlcfg