Re: Re: Bug 67072 resolution for 5.4/5.5
| From: | Marco Pivetta | Date: | Thu, 26 Jun 2014 00:39:48 +0000 |
| Subject: | Re: Re: Bug 67072 resolution for 5.4/5.5 | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75082@lists.php.net to get a copy of this message | ||
On 24 June 2014 21:05, Stas Malyshev <smalyshev@sugarcrm.com> wrote:
> Hi!
>
> > I don't see any problem in the fact that you can skip actual
> instantiation
> > of the object. Even if there *is* a problem with that - a lot of
> user-land
>
> The problem is remotely-triggerable DoS and potentially RCE. Not
> sounding bad enough?
>
Hey Stas,
You keep mentioning these two, but don't they assume that the serialized
data is user-provided?
I don't think anybody sane would/should do that in first place, as it would
be already possible to cause RCE just with any class implementing the
Serializable interface.
Yes, laravel did this via super-closure, but there was a security fix for
it recently.
Could you clarify on this particular point?
I see RCEs anywhere user input is used to dynamically instantiate anything
as well, I just think that it is not the case here, as it would be the
developer's fault for granting access to serialized data to the user.
Marco Pivetta
http://twitter.com/Ocramius
http://ocramius.github.com/