Bug #73529 [PATCH]: session_decode() silently fails on wrong input

From: Date: Wed, 10 Jun 2020 10:05:25 +0000
Subject: Bug #73529 [PATCH]: session_decode() silently fails on wrong input
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-227397@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73529&edit=1 ID: 73529 Patch added by: cmb@php.net Reported by: love at sickpeople dot se Summary: session_decode() silently fails on wrong input Status: Assigned Type: Bug Package: Session related PHP Version: 7.1.0RC6 Assigned To: yohgaki Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Fix #73529: session_decode() silently fails on wrong input On GitHub: https://github.com/php/php-src/pull/5698 Patch: https://github.com/php/php-src/pull/5698.patch Previous Comments: ------------------------------------------------------------------------ [2016-11-15 14:55:30] love at sickpeople dot se Description: ------------ The session_decode() returns true on most invalid values. Eg NULL, ints, strings in wrong format and empty strings. The docs state "Returns TRUE on success or FALSE on failure." and invalid input should be considered an error. .. An important aspect of this is passing data serialized with another method than the current "session.serialize_handler". These should be considered an error as well. I think this is implied by the docs: "By default, the unserialization method used is internal to PHP, and is not the same as unserialize(). The serialization method can be set using session.serialize_handler." The following two test scripts shows that setting A as serialize handler and passing input serialized with B leads to a silent error. The $_SESSION is not populated but true is returned. Eg /* Test 1 */ $data = array ('foo' => 'bar'); ini_set ('session.serialize_handler', 'php'); session_start (); var_dump (session_decode (serialize ($data))); var_dump ($_SESSION); /* Test 2 */ ini_set ('session.serialize_handler', 'php_serialize'); session_start (); var_dump (session_decode ('foo|s:3:"bar";')); var_dump ($_SESSION); Test script: --------------- ini_set ('session.serialize_handler', 'php'); session_start (); var_dump (session_decode ("foo")); Expected result: ---------------- session_decode() to return false. Actual result: -------------- session_decode() returns true. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73529&edit=1

« previous php.bugs (#227397) next »