diff options
-rw-r--r-- | ext/standard/var_unserializer.re | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/ext/standard/var_unserializer.re b/ext/standard/var_unserializer.re index 613dd32c6f..a774946d91 100644 --- a/ext/standard/var_unserializer.re +++ b/ext/standard/var_unserializer.re @@ -477,6 +477,10 @@ PHPAPI int php_var_unserialize(UNSERIALIZE_PARAMETER) "a:" uiv ":" "{" { int elements = parse_iv(start + 2); + if (elements < 0) { + return 0; + } + *p = YYCURSOR; INIT_PZVAL(*rval); |