Bug #77302 [Asn]: Unserialize decode issue

From: Date: Thu, 03 Jan 2019 10:26:03 +0000
Subject: Bug #77302 [Asn]: Unserialize decode issue
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218776@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77302&edit=1

 ID:                 77302
 Updated by:         nikic@php.net
 Reported by:        sh at analogic dot cz
 Summary:            Unserialize decode issue
 Status:             Assigned
 Type:               Bug
 Package:            Variables related
 PHP Version:        7.3.0
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

@Sjon provided the following test case with a similar issue: https://3v4l.org/BEobu That one is an instance of bug #66052
though, where the stricter validation in 7.3 makes the unserialization fail rather than return bogus
data.

The case in this report looks different though, as you don't have any "C:" payloads
in the serialized data.


Previous Comments:
------------------------------------------------------------------------
[2018-12-25 13:43:03] php at famoser dot ch

I have managed to create an example to reliably reproduce the behaviour: https://github.com/mangelio/app/blob/php-bug-%2377302/README.BUG77302.md


The example is unfortunately not separated cleanly from the symfony framework and my specific
project; it is therefore still hard to tell how and why the bug is hit. I will try to isolate the
root cause further, but the example may already help others.

------------------------------------------------------------------------
[2018-12-23 10:36:18] me at famoser dot ch

The bug has an issue in the symfony repository on github: https://github.com/symfony/symfony/issues/29459
This PR shows how the serialize/unserialize calls were used: https://github.com/symfony/symfony/pull/29621/files

------------------------------------------------------------------------
[2018-12-19 23:57:43] nikic@php.net

Has the serialized string been produced by a vanilla serialize() call that is not
nested within a Serializable interface or similar? The r:6 reference looks off-by-one to me.

------------------------------------------------------------------------
[2018-12-15 20:02:43] kalle@php.net

Dmitry, can you please clarify?

------------------------------------------------------------------------
[2018-12-15 13:08:01] cmb@php.net

This behavioral change has been introduced by commit f26fc52[1].
It doesn't appear that the former behavior was correct, though,
since
    s:9:" * domain";r:6
has been unserialized as
    ["domain":protected] => bool(true)

[1] <http://git.php.net/?p=php-src.git;a=commit;h=f26fc527da442943892f265ea48d94a22c29b2bc>

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77302


--
Edit this bug report at https://bugs.php.net/bug.php?id=77302&edit=1


Thread (15 messages)

« previous php.bugs (#218776) next »