Sec Bug->Bug #75044 [Opn]: Object Injection in PHP's WDDX Serialization

From: Date: Sun, 13 Aug 2017 19:40:09 +0000
Subject: Sec Bug->Bug #75044 [Opn]: Object Injection in PHP's WDDX Serialization
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210662@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75044&edit=1 ID: 75044 Updated by: cmb@php.net Reported by: taoguangchen at icloud dot com Summary: Object Injection in PHP's WDDX Serialization Status: Open -Type: Security +Type: Bug Package: WDDX related Operating System: * PHP Version: 5.6.31 Block user comment: N Private report: Y New Comment: > it would be basically in the same class as unserialize, with > same (none) security guarantees as it seems. Indeed, it is; see <http://news.php.net/php.internals/100183> and <http://svn.php.net/viewvc?view=revision&revision=342852>. Previous Comments: ------------------------------------------------------------------------ [2017-08-07 19:50:44] stas@php.net The proposed fix doesn't seem to fix anything in fact, as it's changing serialization, not unserialization, but the question is should we consider this an issue? I.e. if wddx supports live php objects, it would be basically in the same class as unserialize, with same (none) security guarantees as it seems. ------------------------------------------------------------------------ [2017-08-07 10:20:14] taoguangchen at icloud dot com Description: ------------ PoC 1: ``` class ryat { var $hi; function __wakeup() { echo 'hi'; } function __destruct() { echo $this->hi; } } $array = ['php_class_name'=>'ryat', 'hi'=>'ryat']; wddx_deserialize(wddx_serialize_value($array)); ``` PoC 2: ``` ini_set('session.serialize_handler', 'wddx'); session_start(); $array = ['php_class_name'=>'ryat', 'hi'=>'ryat']; $_SESSION['ryat'] = $array; session_decode(session_encode()); class ryat { var $hi; function __wakeup() { echo 'hi'; } function __destruct() { echo $this->hi; } } ``` Fix: ``` static void php_wddx_serialize_array(wddx_packet *packet, zval *arr) { ... if (is_struct) { ent_type = zend_hash_get_current_key_ex(target_hash, &key, &key_len, &idx, 0, NULL); if (ent_type == HASH_KEY_IS_STRING) { + if (!strcmp(key, PHP_CLASS_NAME_VAR)) { + continue; + } php_wddx_serialize_var(packet, *ent, key, key_len TSRMLS_CC); ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75044&edit=1

« previous php.bugs (#210662) next »