Bug #81732 [Dup->Opn]: unserialize __wakeup bypass
| From: | linletianoot at github dot com | Date: | Thu, 29 Sep 2022 05:35:36 +0000 |
| Subject: | Bug #81732 [Dup->Opn]: unserialize __wakeup bypass | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-242488@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=81732&edit=1
ID: 81732
User updated by: linletianoot at github dot com
Reported by: linletianoot at github dot com
Summary: unserialize __wakeup bypass
-Status: Duplicate
+Status: Open
Type: Bug
Package: Unknown/Other Function
Operating System: Windows/Linux
PHP Version: 7.4.30
Assigned To: cmb
Block user comment: N
Private report: Y
New Comment:
How can I change Bug Type from Security to Bug
Previous Comments:
------------------------------------------------------------------------
[2022-09-27 14:42:28] cmb@php.net
Closing as duplicate of <https://github.com/php/php-src/issues/9618>.
------------------------------------------------------------------------
[2022-09-27 10:57:33] cmb@php.net
> this bug PHPBUG#72663 also bypass __wakeup, why is it not a
> problem for me to bypass a later version of __wakeup?
Because we adopted a new security classification[1] in the
meantime.
> How can I change Bug Type from Security to Bug
Please file a ticket at <https://github.com/php/php-src/issues>,
because this bug tracker is only for security issues. Note that
PHP 7.4 is no longer actively supported, so that regular bug fixes
will not be applied; however, it seems the behavior affects newer
versions, too.
[1] <https://wiki.php.net/security>
------------------------------------------------------------------------
[2022-09-27 09:05:14] linletianoot at github dot com
How can I change Bug Type from Security to Bug
------------------------------------------------------------------------
[2022-09-27 08:58:17] linletianoot at github dot com
https://bugs.php.net/bug.php?id=72663
this bug PHPBUG#72663 also bypass __wakeup, why is it not a problem for me to bypass a later version
of __wakeup?
------------------------------------------------------------------------
[2022-09-27 07:55:19] remi@php.net
unserialize is documented as unsecure on untrusted input
https://www.php.net/manual/en/function.unserialize.php
So this cannot be considered as a security issue.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=81732
--
Edit this bug report at https://bugs.php.net/bug.php?id=81732&edit=1