Bug #79880 [Opn]: Fatal error: Uncaught Error: Invalid serialization data for DateTime object
| From: | nikic@php.net | Date: | Wed, 22 Jul 2020 14:42:16 +0000 |
| Subject: | Bug #79880 [Opn]: Fatal error: Uncaught Error: Invalid serialization data for DateTime object | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-228178@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79880&edit=1
ID: 79880
Updated by: nikic@php.net
Reported by: isharafa at unb dot ca
Summary: Fatal error: Uncaught Error: Invalid serialization
data for DateTime object
Status: Open
Type: Bug
Package: Date/time related
Operating System: Ubuntu
PHP Version: 7.4.8
Block user comment: N
Private report: N
New Comment:
I still don't understand what the supposed bug here is. Unserialization throwing exceptions is
completely normal. You get a fatal error because you did not catch the exception.
Previous Comments:
------------------------------------------------------------------------
[2020-07-22 14:16:45] isharafa at unb dot ca
When I modify the datetime object, it just return false, but with this specific test case I get the
Fatal Error. That's why I reported this bug.
------------------------------------------------------------------------
[2020-07-22 12:26:49] cmb@php.net
So this is obviously not a bug.
------------------------------------------------------------------------
[2020-07-22 10:59:42] isharafa at unb dot ca
Yes.
------------------------------------------------------------------------
[2020-07-21 23:39:21] requinix@php.net
What's the bug? You're crafting a custom serialized string (which is already a bad thing)
containing an invalid date string that DateTime would have rejected (so the object shouldn't
even exist in the first place) and when you try to unserialize it you get an exception (as opposed
to a crash).
------------------------------------------------------------------------
[2020-07-21 22:10:59] isharafa at unb dot ca
Description:
------------
I was fuzzing PHP to find a bug in unserialize function and I got the following bug:
Stack trace:
#0 [internal function]: DateTime->__wakeup()
#1 Command line code(1): unserialize('O:8:"DateTime":...')
#2 {main}
thrown in Command line code on line 1
You can reproduce that using the following command.
echo -ne
'O:8:"DateTime":3:{s:4:"date";s:26:"2fe";01-one";s:10"Z.012345";s:13:"timezone_type";i:2;s:8:"timezone";s:1:"Z";}'
| ./sapi/cli/php -r 'unserialize(file_get_contents("php://stdin"));'
Test script:
---------------
echo -ne
'O:8:"DateTime":3:{s:4:"date";s:26:"2fe";01-one";s:10"Z.012345";s:13:"timezone_type";i:2;s:8:"timezone";s:1:"Z";}'
| ./sapi/cli/php -r 'unserialize(file_get_contents("php://stdin"));'
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79880&edit=1