diff options
| author | Stanislav Malyshev <stas@php.net> | 2020-01-20 22:47:28 -0800 |
|---|---|---|
| committer | Stanislav Malyshev <stas@php.net> | 2020-01-20 22:47:28 -0800 |
| commit | 545f77d313bd201ebd716cbd22cc098390ae0757 (patch) | |
| tree | 9a0b4c2eb38a929d1a8a2d25eca8a287e11b080e /ext/session/tests | |
| parent | aaa1f90e3f90c24098fa55a7b868fdca0b89ee25 (diff) | |
| parent | a29c79338106349897c48c4e82b1bec5d9aa4414 (diff) | |
| download | php-git-545f77d313bd201ebd716cbd22cc098390ae0757.tar.gz | |
Merge branch 'PHP-7.4'
* PHP-7.4:
Update NEWS
Fix bug #79037 (global buffer-overflow in `mbfl_filt_conv_big5_wchar`)
Fix #79099: OOB read in php_strip_tags_ex
Fix #79091: heap use-after-free in session_create_id()
Diffstat (limited to 'ext/session/tests')
| -rw-r--r-- | ext/session/tests/bug79091.phpt | 67 |
1 files changed, 67 insertions, 0 deletions
diff --git a/ext/session/tests/bug79091.phpt b/ext/session/tests/bug79091.phpt new file mode 100644 index 0000000000..1d14427159 --- /dev/null +++ b/ext/session/tests/bug79091.phpt @@ -0,0 +1,67 @@ +--TEST-- +Bug #79091 (heap use-after-free in session_create_id()) +--SKIPIF-- +<?php +if (!extension_loaded('session')) die('skip session extension not available'); +?> +--FILE-- +<?php +class MySessionHandler implements SessionHandlerInterface, SessionIdInterface, SessionUpdateTimestampHandlerInterface +{ + public function close() + { + return true; + } + + public function destroy($session_id) + { + return true; + } + + public function gc($maxlifetime) + { + return true; + } + + public function open($save_path, $session_name) + { + return true; + } + + public function read($session_id) + { + return ''; + } + + public function write($session_id, $session_data) + { + return true; + } + + public function create_sid() + { + return uniqid(); + } + + public function updateTimestamp($key, $val) + { + return true; + } + + public function validateId($key) + { + return false; + } +} + +ob_start(); +var_dump(session_set_save_handler(new MySessionHandler())); +var_dump(session_start()); +ob_flush(); +session_create_id(); +?> +--EXPECTF-- +bool(true) +bool(true) + +Warning: session_create_id(): Failed to create new ID in %s on line %d |
