Eval use in XML_RPC

From: Date: Thu, 28 Jul 2005 19:40:05 +0000
Subject: Eval use in XML_RPC
Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-39005@lists.php.net to get a copy of this message
After the last security problems in XML_RPC im surprised to see that no one has went and removed the use the eval from the code. From my quick audit I see no area where it actual needs to be used, and just from a security standpoint I don't think eval should be allowed in Any PEAR code. For example line 1629 of RPC.php is: @eval('$b->'.$id.' = $cont;'); This can easily be replaced by $b->$id = $cont; eval is now removed so things run faster, plus there is no possible exploit from a poorly escaped value in $id The other used of eval is at line 1331 @eval('$v=' . $XML_RPC_xh[$parser]['st'] . '; $allOK=1;'); This seems to be used mainly to handle complex data types like arrays, though even strings and objects are pushed through it. Removing this will take reworking the XML_RPC_se function so its not a simple one liner, but it shouldn't be that hard to redo if you know how the process actually works. -josh

« previous php.pear.dev (#39005) next »