Re: HashDoS

From: Date: Thu, 22 Sep 2016 21:34:45 +0000
Subject: Re: HashDoS
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17  Groups: php.internals 
Request: Send a blank email to internals+get-96103@lists.php.net to get a copy of this message
> Am 22.9.2016 um 22:08 schrieb Stanislav Malyshev <smalyshev@gmail.com>: > > Hi! > >> Yeah it introduces new functions for updating hash which is used by json >> for updating array and it's also in std object handler which is used when >> updating json object. For some other bits like updating array, it will stay >> with fatal. The thing is that json parser can then easily check if there >> was an exception and if so, it will set JSON_ERROR_DEPTH and clear it. It >> seems much better though. > > I'm not sure why special handling for JSON? JSON is certainly not the > only way user data can be ingested and the problem of hash collision is > common to all these ways. > > -- > Stas Malyshev > smalyshev@gmail.com <mailto:smalyshev@gmail.com> The patch is not only targeting JSON. He just used JSON as an example. Every function generating arrays with keys based on user-defined input needs to be updated. I’m going to update the patch soon and will notify you then. Bob

« previous php.internals (#96103) next »