Sec Bug->Bug #75044 [Opn]: Object Injection in PHP's WDDX Serialization
| From: | cmb@php.net | Date: | Sun, 13 Aug 2017 19:40:09 +0000 |
| Subject: | Sec Bug->Bug #75044 [Opn]: Object Injection in PHP's WDDX Serialization | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210662@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75044&edit=1
ID: 75044
Updated by: cmb@php.net
Reported by: taoguangchen at icloud dot com
Summary: Object Injection in PHP's WDDX Serialization
Status: Open
-Type: Security
+Type: Bug
Package: WDDX related
Operating System: *
PHP Version: 5.6.31
Block user comment: N
Private report: Y
New Comment:
> it would be basically in the same class as unserialize, with
> same (none) security guarantees as it seems.
Indeed, it is; see <http://news.php.net/php.internals/100183> and
<http://svn.php.net/viewvc?view=revision&revision=342852>.
Previous Comments:
------------------------------------------------------------------------
[2017-08-07 19:50:44] stas@php.net
The proposed fix doesn't seem to fix anything in fact, as it's changing serialization, not
unserialization, but the question is should we consider this an issue? I.e. if wddx supports live
php objects, it would be basically in the same class as unserialize, with same (none) security
guarantees as it seems.
------------------------------------------------------------------------
[2017-08-07 10:20:14] taoguangchen at icloud dot com
Description:
------------
PoC 1:
```
class ryat {
var $hi;
function __wakeup() {
echo 'hi';
}
function __destruct() {
echo $this->hi;
}
}
$array = ['php_class_name'=>'ryat', 'hi'=>'ryat'];
wddx_deserialize(wddx_serialize_value($array));
```
PoC 2:
```
ini_set('session.serialize_handler', 'wddx');
session_start();
$array = ['php_class_name'=>'ryat', 'hi'=>'ryat'];
$_SESSION['ryat'] = $array;
session_decode(session_encode());
class ryat {
var $hi;
function __wakeup() {
echo 'hi';
}
function __destruct() {
echo $this->hi;
}
}
```
Fix:
```
static void php_wddx_serialize_array(wddx_packet *packet, zval *arr)
{
...
if (is_struct) {
ent_type = zend_hash_get_current_key_ex(target_hash, &key, &key_len, &idx, 0, NULL);
if (ent_type == HASH_KEY_IS_STRING) {
+ if (!strcmp(key, PHP_CLASS_NAME_VAR)) {
+ continue;
+ }
php_wddx_serialize_var(packet, *ent, key, key_len TSRMLS_CC);
```
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75044&edit=1