Re: Re: Bug 67072 resolution for 5.4/5.5

From: Date: Thu, 26 Jun 2014 01:00:12 +0000
Subject: Re: Re: Bug 67072 resolution for 5.4/5.5
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18  Groups: php.internals 
Request: Send a blank email to internals+get-75083@lists.php.net to get a copy of this message
Hi! > You keep mentioning these two, but don't they assume that the serialized > data is user-provided? Yes, they do. > I don't think anybody sane would/should do that in first place, as it Simple search on github suggests otherwise. > would be already possible to cause RCE just with any class implementing > the Serializable interface. Not sure how you could do that, could you please explain how would you cause that? > I see RCEs anywhere user input is used to dynamically instantiate > anything as well, I just think that it is not the case here, as it would > be the developer's fault for granting access to serialized data to the user. I'm not sure what is the problem with simple instantiation - of course, this runs the ctor and unserialize methods, but those are supposed to be able to handle external data. I was, of course, speaking of running arbitrary code on C level, not just PHP methods purposed to handle the data by the developers. -- Stanislav Malyshev, Software Architect SugarCRM: http://www.sugarcrm.com/

« previous php.internals (#75083) next »