#47174 [Opn->Asn]: base64_decode interprets pad char in mid string as terminator
| From: | iliaa@php.net | Date: | Wed, 21 Jan 2009 15:10:06 +0000 |
| Subject: | #47174 [Opn->Asn]: base64_decode interprets pad char in mid string as terminator | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-133113@lists.php.net to get a copy of this message | ||
ID: 47174
Updated by: iliaa@php.net
Reported By: rrichards@php.net
-Status: Open
+Status: Assigned
Bug Type: *URL Functions
Operating System: *
PHP Version: 5.2.8
-Assigned To:
+Assigned To: iliaa
Previous Comments:
------------------------------------------------------------------------
[2009-01-20 21:04:03] rrichards@php.net
Description:
------------
base64_decode handles a pad as the end of data even when it is not
terminating a string, in which case it really should be handled as
non-
alphabet characters. From rfc 3548 2.3: "Furthermore, such
specifications may consider the pad character, "=", as not part of the
base alphabet until the end of the string."
By ignoring all data after the pad, it is difficult to work with
signature based technologies where the base64
decoded octects must be compared to determine validity. PHP allows for
additional data to be added to a signature which ends up being ignored
when compared, while other implementations do not.
Reproduce code:
---------------
if (base64_decode("dGVzdA==") == base64_decode("dGVzdA==CRAP")) {
echo "Same octect data - Signature Valid";
} else {
echo "Invalid Signature";
}
Expected result:
----------------
Invalid Signature
Actual result:
--------------
Same octect data - Signature Valid
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=47174&edit=1