Sec Bug->Doc #70070 [Opn->Fbk]: wddx_deserialize() undocumented unsafe deserialization

From: Date: Tue, 14 Jul 2015 19:07:30 +0000
Subject: Sec Bug->Doc #70070 [Opn->Fbk]: wddx_deserialize() undocumented unsafe deserialization
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-12523@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70070&edit=1 ID: 70070 Updated by: stas@php.net Reported by: andrea dot palazzo at truel dot it Summary: wddx_deserialize() undocumented unsafe deserialization -Status: Open +Status: Feedback -Type: Security +Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant Block user comment: N Private report: Y New Comment: I don't see where the problem is. __wakeup is documented as handler for unserialization, no wonder it is called for unserialization. Previous Comments: ------------------------------------------------------------------------ [2015-07-14 12:22:16] andrea dot palazzo at truel dot it Description: ------------ Hello, the problem here is basically the same described in #69617 for yaml_parse_*. When deserializing a wddx serialized string through wddx_deserialize(), in fact, php_wddx_pop_element() calls the __wakeup() method of every php_class_name instance, which represents serialized PHP objects. wddx.c:945 if (Z_TYPE_P(ent1->data) == IS_OBJECT) { zval *fname, *retval = NULL; MAKE_STD_ZVAL(fname); ZVAL_STRING(fname, "__wakeup", 1); call_user_function_ex(NULL, &ent1->data, fname, &retval, 0, 0, 0, NULL TSRMLS_CC); Test script: --------------- $ cat wddx.php <?php class Pwn { function __wakeup() { echo "Being called\n"; } } $x = "<wddxPacket version='1.0'><header/><data><struct><var name='php_class_name'><string>Pwn</string></var></struct></data></wddxPacket>"; wddx_deserialize($x); ?> --------- $ php wddx.php Being called ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70070&edit=1

« previous php.doc.bugs (#12523) next »