Bug #73054 [Csd->ReO]: default option ignored when object passed to int filter

From: Date: Wed, 07 Jun 2017 22:10:08 +0000
Subject: Bug #73054 [Csd->ReO]: default option ignored when object passed to int filter
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209408@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73054&edit=1 ID: 73054 Updated by: yohgaki@php.net Reported by: dormilich at netscape dot net Summary: default option ignored when object passed to int filter -Status: Closed +Status: Re-Opened Type: Bug Package: Filter related Operating System: Mac OS X 10.11.6 PHP Version: 5.6.25 -Assigned To: cmb +Assigned To: yohgaki Block user comment: N Private report: N New Comment: Thanks, I'm responsible for this then. New OWASP TOP 10 considers current behavior as vulnerability. I'll submit change proposal. Previous Comments: ------------------------------------------------------------------------ [2017-06-06 15:13:03] cmb@php.net > Currently, VALIDATE filter returns default values for _invalid_ > parameter value/type. Indeed, and this behavior is documented[1]: | When default is set to option, default's value is used if value | is not validated. This part of the documentation has been committed by you, by the way, see <http://svn.php.net/viewvc?view=revision&revision=331940>. Anyhow, this bug fix only changes the behavior with regard to objects to be consistent with the behavior of otherwise invalid values, see <https://3v4l.org/IVO7g>, so please open a new ticket if you think the behavior is erroneous. [1] <http://php.net/manual/en/filter.filters.validate.php> ------------------------------------------------------------------------ [2017-06-04 01:38:35] yohgaki@php.net I came across this bug fix bug. Currently, VALIDATE filter returns default values for _invalid_ parameter value/type. Sanitizing filter may ignore _invalid_ parameter value/type. However, validation filter must not ignore _invalid_ parameter and must not use default value. It should treat invalid parameters as error. BTW, ignoring invalid values is now considered as security vulnerability. See OWASP TOP 10 2017 edition RC. (A7 Insufficient Attack Protection) ------------------------------------------------------------------------ [2016-10-17 10:08:28] bwoebi@php.net Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=23e721fc9303dd7423f989f6ff360cdff74aeca1 Log: Fix #73054: default option ignored when object passed to int filter ------------------------------------------------------------------------ [2016-09-09 12:52:30] cmb@php.net Automatic comment on behalf of cmbecker69@gmx.de Revision: http://git.php.net/?p=php-src.git;a=commit;h=23e721fc9303dd7423f989f6ff360cdff74aeca1 Log: Fix #73054: default option ignored when object passed to int filter ------------------------------------------------------------------------ [2016-09-09 10:23:16] cmb@php.net I can confirm both issues: <https://3v4l.org/mAtsv> and <https://3v4l.org/qEUtH>. The first issue has been introduced with the fix for bug #49274, where the function bails out too early thereby ignoring any default value. The second issue is actually a duplicate of bug #67167, which has been fixed (in this regard) only as of PHP 7. The fix should be backported to PHP 5.6. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=73054 -- Edit this bug report at https://bugs.php.net/bug.php?id=73054&edit=1

« previous php.bugs (#209408) next »