php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #70070 wddx_deserialize() undocumented unsafe deserialization
Submitted: 2015-07-14 12:22 UTC Modified: 2015-07-14 20:14 UTC
From: andrea dot palazzo at truel dot it Assigned: cmb (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
View Developer Edit
Welcome! If you don't have a Git account, you can't do anything here.
If you reported this bug, you can edit this bug over here.
(description)
Block user comment
Status: Assign to:
Package:
Bug Type:
Summary:
From: andrea dot palazzo at truel dot it
New email:
PHP Version: OS:

 

 [2015-07-14 12:22 UTC] andrea dot palazzo at truel dot it
Description:
------------
Hello,
the problem here is basically the same described in #69617 for yaml_parse_*.

When deserializing a wddx serialized string through wddx_deserialize(), in fact, php_wddx_pop_element() calls the __wakeup() method of every php_class_name instance, which represents serialized PHP objects.

wddx.c:945

if (Z_TYPE_P(ent1->data) == IS_OBJECT) {
  zval *fname, *retval = NULL;

  MAKE_STD_ZVAL(fname);
  ZVAL_STRING(fname, "__wakeup", 1);
 
  call_user_function_ex(NULL, &ent1->data, fname, &retval, 0, 0, 0, NULL TSRMLS_CC);

Test script:
---------------
$ cat wddx.php

<?php

class Pwn {

	function __wakeup() {
		echo "Being called\n";
	}

}

$x = "<wddxPacket version='1.0'><header/><data><struct><var name='php_class_name'><string>Pwn</string></var></struct></data></wddxPacket>";

wddx_deserialize($x);

?>

---------


$ php wddx.php
Being called



Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2015-07-14 19:07 UTC] stas@php.net
-Status: Open +Status: Feedback -Type: Security +Type: Documentation Problem
 [2015-07-14 19:07 UTC] stas@php.net
I don't see where the problem is. __wakeup is documented as handler for unserialization, no wonder it is called for unserialization.
 [2015-07-14 20:00 UTC] cmb@php.net
-Status: Feedback +Status: Verified -Assigned To: +Assigned To: cmb
 [2015-07-14 20:00 UTC] cmb@php.net
It seems to be appropriate to add a warning to the docs as it's
done for unserialize()[1]:

| Do not pass untrusted user input to unserialize(). [...]

[1] <http://www.php.net/manual/en/function.unserialize.php#refsect1-function.unserialize-notes>
 [2015-07-14 20:13 UTC] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&amp;revision=337163
Log: added warning regarding untrusted user input (fixes #70070)
 [2015-07-14 20:14 UTC] cmb@php.net
-Status: Verified +Status: Closed
 [2015-07-14 20:14 UTC] cmb@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.

Thank you for the report, and for helping us make our documentation better.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Sat Oct 10 00:00:01 2026 UTC