Sec Bug->Bug #81732 [Opn->Dup]: unserialize __wakeup bypass
| From: | cmb@php.net | Date: | Tue, 27 Sep 2022 14:42:28 +0000 |
| Subject: | Sec Bug->Bug #81732 [Opn->Dup]: unserialize __wakeup bypass | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-242468@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81732&edit=1
ID: 81732
Updated by: cmb@php.net
Reported by: linletianoot at github dot com
Summary: unserialize __wakeup bypass
-Status: Open
+Status: Duplicate
-Type: Security
+Type: Bug
Package: Unknown/Other Function
Operating System: Windows/Linux
PHP Version: 7.4.30
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
Closing as duplicate of <https://github.com/php/php-src/issues/9618>.
Previous Comments:
------------------------------------------------------------------------
[2022-09-27 10:57:33] cmb@php.net
> this bug PHPBUG#72663 also bypass __wakeup, why is it not a
> problem for me to bypass a later version of __wakeup?
Because we adopted a new security classification[1] in the
meantime.
> How can I change Bug Type from Security to Bug
Please file a ticket at <https://github.com/php/php-src/issues>,
because this bug tracker is only for security issues. Note that
PHP 7.4 is no longer actively supported, so that regular bug fixes
will not be applied; however, it seems the behavior affects newer
versions, too.
[1] <https://wiki.php.net/security>
------------------------------------------------------------------------
[2022-09-27 09:05:14] linletianoot at github dot com
How can I change Bug Type from Security to Bug
------------------------------------------------------------------------
[2022-09-27 08:58:17] linletianoot at github dot com
https://bugs.php.net/bug.php?id=72663
this bug PHPBUG#72663 also bypass __wakeup, why is it not a problem for me to bypass a later version
of __wakeup?
------------------------------------------------------------------------
[2022-09-27 07:55:19] remi@php.net
unserialize is documented as unsecure on untrusted input
https://www.php.net/manual/en/function.unserialize.php
So this cannot be considered as a security issue.
------------------------------------------------------------------------
[2022-09-27 06:48:45] linletianoot at github dot com
affect version include 7.4.x-7.4.30 7.3.x
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81732
--
Edit this bug report at https://bugs.php.net/bug.php?id=81732&edit=1