Re: Re: Bug 67072 resolution for 5.4/5.5

From: Date: Thu, 26 Jun 2014 00:39:48 +0000
Subject: Re: Re: Bug 67072 resolution for 5.4/5.5
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17  Groups: php.internals 
Request: Send a blank email to internals+get-75082@lists.php.net to get a copy of this message
On 24 June 2014 21:05, Stas Malyshev <smalyshev@sugarcrm.com> wrote: > Hi! > > > I don't see any problem in the fact that you can skip actual > instantiation > > of the object. Even if there *is* a problem with that - a lot of > user-land > > The problem is remotely-triggerable DoS and potentially RCE. Not > sounding bad enough? > Hey Stas, You keep mentioning these two, but don't they assume that the serialized data is user-provided? I don't think anybody sane would/should do that in first place, as it would be already possible to cause RCE just with any class implementing the Serializable interface. Yes, laravel did this via super-closure, but there was a security fix for it recently. Could you clarify on this particular point? I see RCEs anywhere user input is used to dynamically instantiate anything as well, I just think that it is not the case here, as it would be the developer's fault for granting access to serialized data to the user. Marco Pivetta http://twitter.com/Ocramius http://ocramius.github.com/

« previous php.internals (#75082) next »