Doc #70070 [Fbk->Ver]: wddx_deserialize() undocumented unsafe deserialization

From: Date: Tue, 14 Jul 2015 20:00:15 +0000
Subject: Doc #70070 [Fbk->Ver]: wddx_deserialize() undocumented unsafe deserialization
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-12524@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70070&edit=1 ID: 70070 Updated by: cmb@php.net Reported by: andrea dot palazzo at truel dot it Summary: wddx_deserialize() undocumented unsafe deserialization -Status: Feedback +Status: Verified Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: It seems to be appropriate to add a warning to the docs as it's done for unserialize()[1]: | Do not pass untrusted user input to unserialize(). [...] [1] <http://www.php.net/manual/en/function.unserialize.php#refsect1-function.unserialize-notes> Previous Comments: ------------------------------------------------------------------------ [2015-07-14 19:07:28] stas@php.net I don't see where the problem is. __wakeup is documented as handler for unserialization, no wonder it is called for unserialization. ------------------------------------------------------------------------ [2015-07-14 12:22:16] andrea dot palazzo at truel dot it Description: ------------ Hello, the problem here is basically the same described in #69617 for yaml_parse_*. When deserializing a wddx serialized string through wddx_deserialize(), in fact, php_wddx_pop_element() calls the __wakeup() method of every php_class_name instance, which represents serialized PHP objects. wddx.c:945 if (Z_TYPE_P(ent1->data) == IS_OBJECT) { zval *fname, *retval = NULL; MAKE_STD_ZVAL(fname); ZVAL_STRING(fname, "__wakeup", 1); call_user_function_ex(NULL, &ent1->data, fname, &retval, 0, 0, 0, NULL TSRMLS_CC); Test script: --------------- $ cat wddx.php <?php class Pwn { function __wakeup() { echo "Being called\n"; } } $x = "<wddxPacket version='1.0'><header/><data><struct><var name='php_class_name'><string>Pwn</string></var></struct></data></wddxPacket>"; wddx_deserialize($x); ?> --------- $ php wddx.php Being called ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70070&edit=1

« previous php.doc.bugs (#12524) next »