Bug #77178 [Com]: Session id collision detection is broken

From: Date: Tue, 11 Feb 2020 17:29:00 +0000
Subject: Bug #77178 [Com]: Session id collision detection is broken
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-225503@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77178&edit=1 ID: 77178 Comment by: derek at garudacrafts dot com Reported by: riikka dot kalliomaki at gmail dot com Summary: Session id collision detection is broken Status: Assigned Type: Bug Package: Session related PHP Version: 7.2.12 Assigned To: yohgaki Block user comment: N Private report: N New Comment: In regards to my previous comment, please be advised that I think the issue with calling session_create_id() generating the erroneous PHP Warning "session_create_id(): Failed to create new ID in..." was introduced in the bug fix to #79091 (https://bugs.php.net/bug.php?id=79091). I have added a new comment there with details. Previous Comments: ------------------------------------------------------------------------ [2020-02-11 15:39:20] derek at garudacrafts dot com Since php 7.3, whenever I call session_create_id() I get the PHP Warning "session_create_id(): Failed to create new ID in...". However, a new session id IS created, which I can confirm by checking the directory where the session files are saved. So my applications work fine, but my error logs fill up with this new erroneous PHP Warning error message. This does not happen in php 7.2. I have reproduced in both php 7.3 and 7.4, all other things being equal. Could the changes made to the session id collision detection as described in this bug report here have anything to do with it? ------------------------------------------------------------------------ [2019-02-02 03:00:36] kalle@php.net @yohgaki, given the no response from any RM, I think that since it changes the calling procedures for session handlers, it should possibly only go into 7.4 if the way handler callbacks are called changes for backwards compatibility to not introduce regressions for actively supported releases. As you maintain the session module, then any part that you deep a security risk as apart of this report should be fixed in a BC compliant manner for versions as low as 7.1. I personally do not see a high threat here and therefore I'm gonna open the report from its private state. ------------------------------------------------------------------------ [2018-12-10 09:36:26] yohgaki@php.net RMs, how this should be proceeded? Fix this as normal bug or minor security fix? ------------------------------------------------------------------------ [2018-11-21 12:25:32] yohgaki@php.net I don't mind fixing this as minor security fix. i.e. Fix this from PHP 5.6. This doesn't require CVE, IMO. Any comments? ------------------------------------------------------------------------ [2018-11-21 12:18:47] yohgaki@php.net I suppose this can be fixed as normal bug. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77178 -- Edit this bug report at https://bugs.php.net/bug.php?id=77178&edit=1

« previous php.bugs (#225503) next »