diff options
| author | Nikita Popov <nikic@php.net> | 2016-10-23 21:37:36 +0200 |
|---|---|---|
| committer | Nikita Popov <nikic@php.net> | 2016-11-05 23:06:27 +0100 |
| commit | b2af4e8868726a040234de113436c6e4f6372d17 (patch) | |
| tree | 31a3213916606f2602b6a0a821c41f2712766950 | |
| parent | 3d73f718b2715c65be088ef6cb038d30e5d4bb86 (diff) | |
| download | php-git-b2af4e8868726a040234de113436c6e4f6372d17.tar.gz | |
Complete the fix of bug #70172 for PHP 7
| -rw-r--r-- | ext/standard/tests/serialize/bug70172_2.phpt | 6 | ||||
| -rw-r--r-- | ext/standard/var.c | 10 |
2 files changed, 7 insertions, 9 deletions
diff --git a/ext/standard/tests/serialize/bug70172_2.phpt b/ext/standard/tests/serialize/bug70172_2.phpt index dc9067168a..2b12a78edb 100644 --- a/ext/standard/tests/serialize/bug70172_2.phpt +++ b/ext/standard/tests/serialize/bug70172_2.phpt @@ -1,7 +1,5 @@ --TEST-- Bug #70172 - Use After Free Vulnerability in unserialize() ---XFAIL-- -Unfinished merge, needs fix. --FILE-- <?php class obj implements Serializable { @@ -61,10 +59,10 @@ array(2) { [0]=> array(1) { [0]=> - &object(obj2)#%d (1) { + object(obj2)#%d (1) { ["ryat"]=> int(1) } } } -}
\ No newline at end of file +} diff --git a/ext/standard/var.c b/ext/standard/var.c index 472cd62d8f..88719ccb64 100644 --- a/ext/standard/var.c +++ b/ext/standard/var.c @@ -1036,6 +1036,7 @@ PHP_FUNCTION(unserialize) const unsigned char *p; php_unserialize_data_t var_hash; zval *options = NULL, *classes = NULL; + zval *retval; HashTable *class_hash = NULL; if (zend_parse_parameters(ZEND_NUM_ARGS(), "s|a", &buf, &buf_len, &options) == FAILURE) { @@ -1067,22 +1068,21 @@ PHP_FUNCTION(unserialize) } } - if (!php_var_unserialize_ex(return_value, &p, p + buf_len, &var_hash, class_hash)) { + retval = var_tmp_var(&var_hash); + if (!php_var_unserialize_ex(retval, &p, p + buf_len, &var_hash, class_hash)) { PHP_VAR_UNSERIALIZE_DESTROY(var_hash); if (class_hash) { zend_hash_destroy(class_hash); FREE_HASHTABLE(class_hash); } - zval_ptr_dtor(return_value); if (!EG(exception)) { php_error_docref(NULL, E_NOTICE, "Error at offset " ZEND_LONG_FMT " of %zd bytes", (zend_long)((char*)p - buf), buf_len); } RETURN_FALSE; } - /* We should keep an reference to return_value to prevent it from being dtor - in case nesting calls to unserialize */ - var_push_dtor(&var_hash, return_value); + + ZVAL_COPY(return_value, retval); PHP_VAR_UNSERIALIZE_DESTROY(var_hash); if (class_hash) { |
