Doc #70070 [Ver->Csd]: wddx_deserialize() undocumented unsafe deserialization

From: Date: Tue, 14 Jul 2015 20:14:32 +0000
Subject: Doc #70070 [Ver->Csd]: wddx_deserialize() undocumented unsafe deserialization
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-12525@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70070&edit=1 ID: 70070 Updated by: cmb@php.net Reported by: andrea dot palazzo at truel dot it Summary: wddx_deserialize() undocumented unsafe deserialization -Status: Verified +Status: Closed Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant Assigned To: cmb Block user comment: N Private report: N New Comment: This bug has been fixed in the documentation's XML sources. Since the online and downloadable versions of the documentation need some time to get updated, we would like to ask you to be a bit patient. Thank you for the report, and for helping us make our documentation better. Previous Comments: ------------------------------------------------------------------------ [2015-07-14 20:13:56] cmb@php.net Automatic comment from SVN on behalf of cmb Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=337163 Log: added warning regarding untrusted user input (fixes #70070) ------------------------------------------------------------------------ [2015-07-14 20:00:13] cmb@php.net It seems to be appropriate to add a warning to the docs as it's done for unserialize()[1]: | Do not pass untrusted user input to unserialize(). [...] [1] <http://www.php.net/manual/en/function.unserialize.php#refsect1-function.unserialize-notes> ------------------------------------------------------------------------ [2015-07-14 19:07:28] stas@php.net I don't see where the problem is. __wakeup is documented as handler for unserialization, no wonder it is called for unserialization. ------------------------------------------------------------------------ [2015-07-14 12:22:16] andrea dot palazzo at truel dot it Description: ------------ Hello, the problem here is basically the same described in #69617 for yaml_parse_*. When deserializing a wddx serialized string through wddx_deserialize(), in fact, php_wddx_pop_element() calls the __wakeup() method of every php_class_name instance, which represents serialized PHP objects. wddx.c:945 if (Z_TYPE_P(ent1->data) == IS_OBJECT) { zval *fname, *retval = NULL; MAKE_STD_ZVAL(fname); ZVAL_STRING(fname, "__wakeup", 1); call_user_function_ex(NULL, &ent1->data, fname, &retval, 0, 0, 0, NULL TSRMLS_CC); Test script: --------------- $ cat wddx.php <?php class Pwn { function __wakeup() { echo "Being called\n"; } } $x = "<wddxPacket version='1.0'><header/><data><struct><var name='php_class_name'><string>Pwn</string></var></struct></data></wddxPacket>"; wddx_deserialize($x); ?> --------- $ php wddx.php Being called ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70070&edit=1

« previous php.doc.bugs (#12525) next »