Bug #77283 [Opn->Csd]: memory exhausted when unserialize data
Edit report at https://bugs.php.net/bug.php?id=77283&edit=1
ID: 77283
Updated by: nikic@php.net
Reported by: jasonxiale at mail dot ru
Summary: memory exhausted when unserialize data
-Status: Open
+Status: Closed
Type: Bug
Package: Class/Object related
Operating System: Linux(4.15.0-42-generic)
PHP Version: master-Git-2018-12-11 (Git)
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
This has been addressed in the meantime, unserialize() no longer allows allocations larger than the
payload size.
Previous Comments:
------------------------------------------------------------------------
[2018-12-11 16:16:43] jasonxiale at mail dot ru
Description:
------------
when fuzzing php unserialize function using command as:
./sapi/cli/php -r 'unserialize(file_get_contents("php://stdin"));' <
basic_fuzz/fuzzer11/crashes/id\:000000\,sig\:06\,src\:000158+000528\,op\:splice\,rep\:2
I got an error:
Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 42949672960 bytes)
in Command line code on line 1
Test script:
---------------
the base64-ed input is like
base64 basic_fuzz/fuzzer11/crashes/id\:000000\,sig\:06\,src\:000158+000528\,op\:splice\,rep\:2
YTozOntpOjA7YToyOntpOjA7TzoxOiIxIjowNzc3Nzc3Nzc3Ojc3Nzc3Nzc3Nzc3Nzc3Nzc3Nzc3
Nzc3Nzc3Nzc3Nzc7ASkxOip//yI3Nzc3NzQiO31pOkk7YToyOntpOjA7aVwxO2k3N6UXMSNpAAAA
AX0=
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77283&edit=1
Thread (2 messages)