php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #55516 is_callable can be a security vulnerability
Submitted: 2011-08-26 22:25 UTC Modified: 2011-08-26 23:42 UTC
From: thegreatall at gmail dot com Assigned:
Status: Not a bug Package: Documentation problem
PHP Version: Irrelevant OS: N/A
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: thegreatall at gmail dot com
New email:
PHP Version: OS:

 

 [2011-08-26 22:25 UTC] thegreatall at gmail dot com
Description:
------------
If you would be writing a framework or any code that the developer can send a 
parameter though and the receiving code uses is_callable() to test to see if the 
variable is a lambda/closure type, they may be opening them selves up to a 
security vulnerability if the attacker is able to set a string to that variable. I 
recommend adding a note to that function's documentation saying that if you wish 
to check to see if a variable is a lambda/closure use "is_a($var, 'Closure')". I 
know this can be avoided by safe coding, but it can be a huge security issue.

Test script:
---------------
<?php
function buildGrid(array $data){
	echo '<table>';
	foreach($data as $key => $cell){
		if(is_callable($cell)){ // This should be is_a($cell, 'Closure')
			echo $cell($key);
		}else{
			echo '<tr><td>', htmlentities($key), '</td><td>', htmlentities($cell), '</td></tr>';
		}
	}
	echo '</table>';
}

$array = array(
	'id' => $_REQUEST['id'],
	'name' => $_REQUEST['name'],
	'last_name' => $_REQUEST['last_name'],
	function ($key){
		return '<tr><td>A HEADER OR IMAGE OR SOMETHING THAT CANNOT BE EVALUATED OR DISPLAYED UNLESS CALLED AT COMPILE TIME</td></tr>';
	}
);
buildGrid($array);
/*
 * If the attacker sent a request like: 'index.php?id=11111&name=somename&last_name=phpinfo'
 * This will show this attacker all the phpinfo() for the server. This could be vary
 * dangerious if the programmer had a function like showDebugInfo() as the user could possibly
 * get very valuble info.
 */
?>


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-08-26 22:59 UTC] johannes@php.net
-Status: Open +Status: Bogus -Type: Security +Type: Documentation Problem
 [2011-08-26 22:59 UTC] johannes@php.net
It is documented, that strings are callable types. We can't prevent all the ways a PHP developer can shoot in his foot.
 [2011-08-26 23:42 UTC] stas@php.net
Also, you should use "$var instanceof Closure" in this case :)
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Thu Oct 08 03:00:02 2026 UTC