Bug #68920 [Csd]: php_x509_fingerprint_match need stricter checks
Edit report at https://bugs.php.net/bug.php?id=68920&edit=1
ID: 68920
Updated by: rdlowrey@php.net
Reported by: erik at datahack dot se
Summary: php_x509_fingerprint_match need stricter checks
Status: Closed
Type: Bug
Package: OpenSSL related
PHP Version: 5.6.5
Assigned To: rdlowrey
Block user comment: N
Private report: N
New Comment:
This has been corrected in 5.6 and master via the following commit:
http://git.php.net/?p=php-src.git;a=commitdiff;h=241f3c34b89ab55432d5af3fd1e4217540e161a3
Thanks for the report.
Previous Comments:
------------------------------------------------------------------------
[2015-03-04 19:52:22] rdlowrey@php.net
Automatic comment on behalf of rdlowrey
Revision: http://git.php.net/?p=php-src.git;a=commit;h=241f3c34b89ab55432d5af3fd1e4217540e161a3
Log: Fixed bug #68920 (use strict peer_fingerprint input checks)
------------------------------------------------------------------------
[2015-03-04 19:52:07] rdlowrey@php.net
Automatic comment on behalf of rdlowrey
Revision: http://git.php.net/?p=php-src.git;a=commit;h=241f3c34b89ab55432d5af3fd1e4217540e161a3
Log: Fixed bug #68920 (use strict peer_fingerprint input checks)
------------------------------------------------------------------------
[2015-03-04 16:57:57] rdlowrey@php.net
+1 ... fixed locally. Will update/close once I push relevant commits upstream.
------------------------------------------------------------------------
[2015-01-27 12:51:33] erik at datahack dot se
Description:
------------
In php_x509_fingerprint_match() and its caller, due to its logic the "SSL context" option
'peer_fingerprint' may pass and establish the connection with or without a warning, if set
to an invalid value (specifically data type).
Test script:
---------------
<?php
error_reporting(E_ALL);
// pass, warning
var_dump(stream_socket_client("ssl://php.net:443", $errno, $errstr, 30,
STREAM_CLIENT_CONNECT, stream_context_create([
'ssl' => ['verify_peer'=> false, 'peer_fingerprint'
=> true]
])));
// pass, no warning
var_dump(stream_socket_client("ssl://php.net:443", $errno, $errstr, 30,
STREAM_CLIENT_CONNECT, stream_context_create([
'ssl' => ['verify_peer'=> false, 'peer_fingerprint'
=> null]
])));
// pass, no warning
var_dump(stream_socket_client("ssl://php.net:443", $errno, $errstr, 30,
STREAM_CLIENT_CONNECT, stream_context_create([
'ssl' => ['verify_peer'=> false, 'peer_fingerprint'
=> []]
])));
// pass, no warning
var_dump(stream_socket_client("ssl://php.net:443", $errno, $errstr, 30,
STREAM_CLIENT_CONNECT, stream_context_create([
'ssl' => ['verify_peer'=> false, 'peer_fingerprint'
=> ['foo']]
])));
Expected result:
----------------
All these connections should fail or at least give a warning.
Actual result:
--------------
Connection is established in all cases...
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68920&edit=1
Thread (4 messages)