Bug #68920 [Csd]: php_x509_fingerprint_match need stricter checks

From: Date: Wed, 04 Mar 2015 19:54:15 +0000
Subject: Bug #68920 [Csd]: php_x509_fingerprint_match need stricter checks
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191160@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68920&edit=1

 ID:                 68920
 Updated by:         rdlowrey@php.net
 Reported by:        erik at datahack dot se
 Summary:            php_x509_fingerprint_match need stricter checks
 Status:             Closed
 Type:               Bug
 Package:            OpenSSL related
 PHP Version:        5.6.5
 Assigned To:        rdlowrey
 Block user comment: N
 Private report:     N

 New Comment:

This has been corrected in 5.6 and master via the following commit:

http://git.php.net/?p=php-src.git;a=commitdiff;h=241f3c34b89ab55432d5af3fd1e4217540e161a3

Thanks for the report.


Previous Comments:
------------------------------------------------------------------------
[2015-03-04 19:52:22] rdlowrey@php.net

Automatic comment on behalf of rdlowrey
Revision: http://git.php.net/?p=php-src.git;a=commit;h=241f3c34b89ab55432d5af3fd1e4217540e161a3
Log: Fixed bug #68920 (use strict peer_fingerprint input checks)

------------------------------------------------------------------------
[2015-03-04 19:52:07] rdlowrey@php.net

Automatic comment on behalf of rdlowrey
Revision: http://git.php.net/?p=php-src.git;a=commit;h=241f3c34b89ab55432d5af3fd1e4217540e161a3
Log: Fixed bug #68920 (use strict peer_fingerprint input checks)

------------------------------------------------------------------------
[2015-03-04 16:57:57] rdlowrey@php.net

+1 ... fixed locally. Will update/close once I push relevant commits upstream.

------------------------------------------------------------------------
[2015-01-27 12:51:33] erik at datahack dot se

Description:
------------
In php_x509_fingerprint_match() and its caller, due to its logic the "SSL context" option
'peer_fingerprint' may pass and establish the connection with or without a warning, if set
to an invalid value (specifically data type).

Test script:
---------------
<?php

error_reporting(E_ALL);

// pass, warning
var_dump(stream_socket_client("ssl://php.net:443", $errno, $errstr, 30,
STREAM_CLIENT_CONNECT, stream_context_create([
        'ssl' => ['verify_peer'=> false, 'peer_fingerprint'
=> true]
        ])));

// pass, no warning
var_dump(stream_socket_client("ssl://php.net:443", $errno, $errstr, 30,
STREAM_CLIENT_CONNECT, stream_context_create([
        'ssl' => ['verify_peer'=> false, 'peer_fingerprint'
=> null]
        ])));

// pass, no warning
var_dump(stream_socket_client("ssl://php.net:443", $errno, $errstr, 30,
STREAM_CLIENT_CONNECT, stream_context_create([
        'ssl' => ['verify_peer'=> false, 'peer_fingerprint'
=> []]
        ])));

// pass, no warning
var_dump(stream_socket_client("ssl://php.net:443", $errno, $errstr, 30,
STREAM_CLIENT_CONNECT, stream_context_create([
        'ssl' => ['verify_peer'=> false, 'peer_fingerprint'
=> ['foo']]
        ])));


Expected result:
----------------
All these connections should fail or at least give a warning.

Actual result:
--------------
Connection is established in all cases...


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68920&edit=1


Thread (4 messages)

« previous php.bugs (#191160) next »