Bug #67363 [Opn->Fbk]: Unserialize corrupts data
| From: | cmb@php.net | Date: | Sun, 14 Jun 2020 15:40:43 +0000 |
| Subject: | Bug #67363 [Opn->Fbk]: Unserialize corrupts data | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-227473@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67363&edit=1
ID: 67363
Updated by: cmb@php.net
Reported by: mg at artigo dot pl
Summary: Unserialize corrupts data
-Status: Open
+Status: Feedback
Type: Bug
Package: Variables related
Operating System: Irrelavant
PHP Version: Irrelevant
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Does this issue still happen with any of the actively supported
PHP versions[1]?
[1] <https://www.php.net/supported-versions.php>
Previous Comments:
------------------------------------------------------------------------
[2017-01-07 22:15:21] nikic@php.net
@laszlokorte: In that case you're probably hit by bug #66052 (see also my comment on bug
#73253).
------------------------------------------------------------------------
[2017-01-07 22:08:51] php at laszlokorte dot de
@jh1711 You re right. I fixed the bug in the gist. But mainDef is not correctly unserialized in
php<7 anyway and in my real application I still get the "unserialize(): Error at offset 1026
of 1348 byte error" in a similar but more complex situation (deeper nestings, more properties,
but no cycles)
------------------------------------------------------------------------
[2017-01-07 19:57:26] jh1711 at xmail dot net
@laszlokorte, there's a mistake in your gist. Definition::unserialize should pass $data to
unserialize, or use $value as a parameter. Unserializing an uninitialized variable causes the false
values, and not unserializing the parameter messes up the references. See https://3v4l.org/vioIT .
@nikic, imho the cause of bug #66085 is serializing additional data during serialization. Of course
this can result in similar behaviour. See https://3v4l.org/9hVS2 .
------------------------------------------------------------------------
[2017-01-07 18:36:19] php at laszlokorte dot de
@nikic Thanks, indeed the problem of the gist I posted is solved by php7. But in my real application
I now get many "Notice: unserialize(): Error at offset 1026 of 1348 bytes" errors.
------------------------------------------------------------------------
[2017-01-07 17:58:57] nikic@php.net
@laszlokorte: That is most likely bug #66085, which is fixed in PHP 7.0 (but not 5.6).
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67363
--
Edit this bug report at https://bugs.php.net/bug.php?id=67363&edit=1