Doc #70070 [Ver->Csd]: wddx_deserialize() undocumented unsafe deserialization
| From: | cmb@php.net | Date: | Tue, 14 Jul 2015 20:14:32 +0000 |
| Subject: | Doc #70070 [Ver->Csd]: wddx_deserialize() undocumented unsafe deserialization | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12525@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70070&edit=1
ID: 70070
Updated by: cmb@php.net
Reported by: andrea dot palazzo at truel dot it
Summary: wddx_deserialize() undocumented unsafe
deserialization
-Status: Verified
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
Previous Comments:
------------------------------------------------------------------------
[2015-07-14 20:13:56] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=337163
Log: added warning regarding untrusted user input (fixes #70070)
------------------------------------------------------------------------
[2015-07-14 20:00:13] cmb@php.net
It seems to be appropriate to add a warning to the docs as it's
done for unserialize()[1]:
| Do not pass untrusted user input to unserialize(). [...]
[1] <http://www.php.net/manual/en/function.unserialize.php#refsect1-function.unserialize-notes>
------------------------------------------------------------------------
[2015-07-14 19:07:28] stas@php.net
I don't see where the problem is. __wakeup is documented as handler for unserialization, no
wonder it is called for unserialization.
------------------------------------------------------------------------
[2015-07-14 12:22:16] andrea dot palazzo at truel dot it
Description:
------------
Hello,
the problem here is basically the same described in #69617 for yaml_parse_*.
When deserializing a wddx serialized string through wddx_deserialize(), in fact,
php_wddx_pop_element() calls the __wakeup() method of every php_class_name instance, which
represents serialized PHP objects.
wddx.c:945
if (Z_TYPE_P(ent1->data) == IS_OBJECT) {
zval *fname, *retval = NULL;
MAKE_STD_ZVAL(fname);
ZVAL_STRING(fname, "__wakeup", 1);
call_user_function_ex(NULL, &ent1->data, fname, &retval, 0, 0, 0, NULL TSRMLS_CC);
Test script:
---------------
$ cat wddx.php
<?php
class Pwn {
function __wakeup() {
echo "Being called\n";
}
}
$x = "<wddxPacket
version='1.0'><header/><data><struct><var
name='php_class_name'><string>Pwn</string></var></struct></data></wddxPacket>";
wddx_deserialize($x);
?>
---------
$ php wddx.php
Being called
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70070&edit=1