Bug #65698 [Opn->Csd]: certificates validity parsing does not work past 2050
| From: | stas@php.net | Date: | Sun, 08 Jun 2014 21:21:49 +0000 |
| Subject: | Bug #65698 [Opn->Csd]: certificates validity parsing does not work past 2050 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186100@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65698&edit=1
ID: 65698
Updated by: stas@php.net
Reported by: tranzig at gmail dot com
Summary: certificates validity parsing does not work past
2050
-Status: Open
+Status: Closed
Type: Bug
Package: OpenSSL related
PHP Version: master-Git-2013-09-18 (Git)
-Assigned To:
+Assigned To: stas
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
For Windows:
http://windows.php.net/snapshots/
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2014-03-21 15:41:39] oroszisam at gmail dot com
Related To: Bug #66636
------------------------------------------------------------------------
[2014-03-21 15:34:37] oroszisam at gmail dot com
With the fix for CVE-2013-6420, this bug became even more visible.
Now, instead of silently returning an incorrect timestamp, a PHP
warning is thrown for all certificates where the notBefore or
notAfter field is in the GeneralizedTime format, stating that it is an
"illegal ASN1 data type for timestamp", which is an obviously incorrect
statement.
------------------------------------------------------------------------
[2013-09-18 14:51:29] tranzig at gmail dot com
Description:
------------
In asn1_time_to_time_t [ext/openssl/openssl.c], the Y2K bug makes a cameo
appearance:
[...]
*thestr = '\0';
thestr -= 2;
thetime.tm_year = atoi(thestr);
if (thetime.tm_year < 68) {
thetime.tm_year += 100;
}
This piece of code is the part of a backwards UTCTime parser. It moves 2
positions to the left, and converts those two characters to an int.
However, certs with a validity past 2050 contain GeneralizedTime formatted
timestamps allowing 4 characters in the year field instead of the UTCTime this
function parses (badly). [rfc5280, 4.1.2.5]
Test script:
---------------
An example script that demonstrates the problem with a cert expiring 2101:
http://pastebin.com/Yij0q1qn
Expected result:
----------------
Actual time string of validity: 21010828070405Z
parsed with strtotime: 4154655845 [2101-08-28]
parsed with asn1_time_to_time_t: 4154655845 [2101-08-28]
Actual result:
--------------
Actual time string of validity: 21010828070405Z
parsed with strtotime: 4154655845 [2101-08-28]
parsed with asn1_time_to_time_t: 998982245 [2001-08-28]
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65698&edit=1