Bug #81732 [Dup->Opn]: unserialize __wakeup bypass

From: Date: Thu, 29 Sep 2022 05:35:36 +0000
Subject: Bug #81732 [Dup->Opn]: unserialize __wakeup bypass
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242488@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81732&edit=1 ID: 81732 User updated by: linletianoot at github dot com Reported by: linletianoot at github dot com Summary: unserialize __wakeup bypass -Status: Duplicate +Status: Open Type: Bug Package: Unknown/Other Function Operating System: Windows/Linux PHP Version: 7.4.30 Assigned To: cmb Block user comment: N Private report: Y New Comment: How can I change Bug Type from Security to Bug Previous Comments: ------------------------------------------------------------------------ [2022-09-27 14:42:28] cmb@php.net Closing as duplicate of <https://github.com/php/php-src/issues/9618>. ------------------------------------------------------------------------ [2022-09-27 10:57:33] cmb@php.net > this bug PHPBUG#72663 also bypass __wakeup, why is it not a > problem for me to bypass a later version of __wakeup? Because we adopted a new security classification[1] in the meantime. > How can I change Bug Type from Security to Bug Please file a ticket at <https://github.com/php/php-src/issues>, because this bug tracker is only for security issues. Note that PHP 7.4 is no longer actively supported, so that regular bug fixes will not be applied; however, it seems the behavior affects newer versions, too. [1] <https://wiki.php.net/security> ------------------------------------------------------------------------ [2022-09-27 09:05:14] linletianoot at github dot com How can I change Bug Type from Security to Bug ------------------------------------------------------------------------ [2022-09-27 08:58:17] linletianoot at github dot com https://bugs.php.net/bug.php?id=72663 this bug PHPBUG#72663 also bypass __wakeup, why is it not a problem for me to bypass a later version of __wakeup? ------------------------------------------------------------------------ [2022-09-27 07:55:19] remi@php.net unserialize is documented as unsecure on untrusted input https://www.php.net/manual/en/function.unserialize.php So this cannot be considered as a security issue. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81732 -- Edit this bug report at https://bugs.php.net/bug.php?id=81732&edit=1

« previous php.bugs (#242488) next »