diff options
Diffstat (limited to 'ext/standard/tests/serialize/unserialize_leak.phpt')
-rw-r--r-- | ext/standard/tests/serialize/unserialize_leak.phpt | 16 |
1 files changed, 16 insertions, 0 deletions
diff --git a/ext/standard/tests/serialize/unserialize_leak.phpt b/ext/standard/tests/serialize/unserialize_leak.phpt new file mode 100644 index 0000000000..383bcfc075 --- /dev/null +++ b/ext/standard/tests/serialize/unserialize_leak.phpt @@ -0,0 +1,16 @@ +--TEST-- +Unserialize leak in SplObjectStorage +--FILE-- +<?php + +$payload = 'C:16:"SplObjectStorage":113:{x:i:2;O:8:"stdClass":1:{},a:2:{s:4:"prev";i:2;s:4:"next";O:8:"stdClass":0:{}};r:7;,R:2;s:4:"next";;r:3;};m:a:0:{}}'; +try { + var_dump(unserialize($payload)); +} catch (Exception $e) { + echo $e->getMessage(), "\n"; +} + +?> +--EXPECTF-- +Notice: SplObjectStorage::unserialize(): Unexpected end of serialized data in %s on line %d +Error at offset 24 of 113 bytes |