Sec Bug->Bug #81732 [Opn->Dup]: unserialize __wakeup bypass

From: Date: Tue, 27 Sep 2022 14:42:28 +0000
Subject: Sec Bug->Bug #81732 [Opn->Dup]: unserialize __wakeup bypass
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242468@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81732&edit=1 ID: 81732 Updated by: cmb@php.net Reported by: linletianoot at github dot com Summary: unserialize __wakeup bypass -Status: Open +Status: Duplicate -Type: Security +Type: Bug Package: Unknown/Other Function Operating System: Windows/Linux PHP Version: 7.4.30 -Assigned To: +Assigned To: cmb Block user comment: N Private report: Y New Comment: Closing as duplicate of <https://github.com/php/php-src/issues/9618>. Previous Comments: ------------------------------------------------------------------------ [2022-09-27 10:57:33] cmb@php.net > this bug PHPBUG#72663 also bypass __wakeup, why is it not a > problem for me to bypass a later version of __wakeup? Because we adopted a new security classification[1] in the meantime. > How can I change Bug Type from Security to Bug Please file a ticket at <https://github.com/php/php-src/issues>, because this bug tracker is only for security issues. Note that PHP 7.4 is no longer actively supported, so that regular bug fixes will not be applied; however, it seems the behavior affects newer versions, too. [1] <https://wiki.php.net/security> ------------------------------------------------------------------------ [2022-09-27 09:05:14] linletianoot at github dot com How can I change Bug Type from Security to Bug ------------------------------------------------------------------------ [2022-09-27 08:58:17] linletianoot at github dot com https://bugs.php.net/bug.php?id=72663 this bug PHPBUG#72663 also bypass __wakeup, why is it not a problem for me to bypass a later version of __wakeup? ------------------------------------------------------------------------ [2022-09-27 07:55:19] remi@php.net unserialize is documented as unsecure on untrusted input https://www.php.net/manual/en/function.unserialize.php So this cannot be considered as a security issue. ------------------------------------------------------------------------ [2022-09-27 06:48:45] linletianoot at github dot com affect version include 7.4.x-7.4.30 7.3.x ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81732 -- Edit this bug report at https://bugs.php.net/bug.php?id=81732&edit=1

« previous php.bugs (#242468) next »