Doc #70070 [Fbk->Ver]: wddx_deserialize() undocumented unsafe deserialization
| From: | cmb@php.net | Date: | Tue, 14 Jul 2015 20:00:15 +0000 |
| Subject: | Doc #70070 [Fbk->Ver]: wddx_deserialize() undocumented unsafe deserialization | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12524@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70070&edit=1
ID: 70070
Updated by: cmb@php.net
Reported by: andrea dot palazzo at truel dot it
Summary: wddx_deserialize() undocumented unsafe
deserialization
-Status: Feedback
+Status: Verified
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
It seems to be appropriate to add a warning to the docs as it's
done for unserialize()[1]:
| Do not pass untrusted user input to unserialize(). [...]
[1] <http://www.php.net/manual/en/function.unserialize.php#refsect1-function.unserialize-notes>
Previous Comments:
------------------------------------------------------------------------
[2015-07-14 19:07:28] stas@php.net
I don't see where the problem is. __wakeup is documented as handler for unserialization, no
wonder it is called for unserialization.
------------------------------------------------------------------------
[2015-07-14 12:22:16] andrea dot palazzo at truel dot it
Description:
------------
Hello,
the problem here is basically the same described in #69617 for yaml_parse_*.
When deserializing a wddx serialized string through wddx_deserialize(), in fact,
php_wddx_pop_element() calls the __wakeup() method of every php_class_name instance, which
represents serialized PHP objects.
wddx.c:945
if (Z_TYPE_P(ent1->data) == IS_OBJECT) {
zval *fname, *retval = NULL;
MAKE_STD_ZVAL(fname);
ZVAL_STRING(fname, "__wakeup", 1);
call_user_function_ex(NULL, &ent1->data, fname, &retval, 0, 0, 0, NULL TSRMLS_CC);
Test script:
---------------
$ cat wddx.php
<?php
class Pwn {
function __wakeup() {
echo "Being called\n";
}
}
$x = "<wddxPacket
version='1.0'><header/><data><struct><var
name='php_class_name'><string>Pwn</string></var></struct></data></wddxPacket>";
wddx_deserialize($x);
?>
---------
$ php wddx.php
Being called
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70070&edit=1