Bug #51436 [Asn->Csd]: LCG entropy fix insufficient, uniqid leaks entropy, leads to weak session IDs
| From: | pajoye@php.net | Date: | Sun, 05 Apr 2015 05:16:39 +0000 |
| Subject: | Bug #51436 [Asn->Csd]: LCG entropy fix insufficient, uniqid leaks entropy, leads to weak session IDs | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-191826@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=51436&edit=1
ID: 51436
Updated by: pajoye@php.net
Reported by: andreas at andreas dot org
Summary: LCG entropy fix insufficient, uniqid leaks entropy,
leads to weak session IDs
-Status: Assigned
+Status: Closed
Type: Bug
Package: *Encryption and hash functions
Operating System: all
PHP Version: 5.3.2
Assigned To: pajoye
Block user comment: N
Private report: N
New Comment:
Thank you for your bug report. This issue has already been fixed
in the latest released version of PHP, which you can download at
http://www.php.net/downloads.php
Previous Comments:
------------------------------------------------------------------------
[2014-07-15 11:50:48] yohgaki@php.net
I suppose this can be closed, can't this?
------------------------------------------------------------------------
[2010-06-08 15:56:09] pajoye@php.net
I added support for the entropy source to 5.3 and trunk.
See http://svn.php.net/viewvc?view=revision&revision=300273
and
http://svn.php.net/viewvc?view=revision&revision=300278
Will close the bug once we also have defined the default hash (would like to make it a default in
trunk as well).
------------------------------------------------------------------------
[2010-04-09 19:05:46] pajoye@php.net
RAND_pseudo_bytes does pretty much the same anyway, but I would prefer to give a possible not to use
openssl first.
Also this exact function may not be crypto safe. It is not a problem for the session but that will
then not solve the need of a crypto safe function.
------------------------------------------------------------------------
[2010-04-09 18:41:56] crrodriguez at opensuse dot org
I think trying RAND_pseudo_bytes() if -lcrypto is found in the system first and
then your_own_function ight be a suitable approach.
------------------------------------------------------------------------
[2010-04-09 18:18:32] pajoye@php.net
That's the idea but not using zend's mm which is incomplete.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=51436
--
Edit this bug report at https://bugs.php.net/bug.php?id=51436&edit=1