Bug #60632 [Asn->Csd]: openssl_seal fails with AES

From: Date: Sun, 06 Sep 2015 15:40:15 +0000
Subject: Bug #60632 [Asn->Csd]: openssl_seal fails with AES
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195803@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=60632&edit=1

 ID:                 60632
 Updated by:         bukka@php.net
 Reported by:        brett at silcon dot com
 Summary:            openssl_seal fails with AES
-Status:             Assigned
+Status:             Closed
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Ubuntu 12.04 LTS
 PHP Version:        5.4.0-ZS5.6.0
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of bukka
Revision: http://git.php.net/?p=php-src.git;a=commit;h=d47029167dfc2184f9a630a75a55e145bff8b017
Log: Fix bug #60632: openssl_seal fails with AES


Previous Comments:
------------------------------------------------------------------------
[2015-09-01 00:49:45] cmb@php.net

Related To: Bug #70329

------------------------------------------------------------------------
[2015-08-30 18:42:30] bukka@php.net

I think that the patch looks reasonable. I'm just pinging internals if it's ok for 5.6 (it
adds new param...). If so, I will test it, merge it and then port it to 7 as well. If not I will
just disable IV ciphers for 5.6 to prevent segfualt. 

There might be is a small concern with locking issue on TS Win as EVP_SealInit uses RAND_bytes but
it's already case for some already used parts (e.g. gen params for new pkey) so don't
think it should be a blocker here.

------------------------------------------------------------------------
[2015-06-22 21:57:09] calebbegly at gmail dot com

This persists in PHP 5.6.10.

There appear to be some commented out code in the source that attempted to set up some stuff for
adding the initialization vector but the call still just passes NULL in for what should be the
pointer to the IV (unsigned char *).

I have to say I was quite surprised to see that this hasn't been resolved yet.

------------------------------------------------------------------------
[2013-11-18 02:25:22] brett at silcon dot com

I'll have to try it out sometime. The project was deployed 2 years ago with execing command
line tools as a last resort.

Apparently PHP doesn't really care about AES support much. Thanks for looking into it though.

------------------------------------------------------------------------
[2013-11-10 21:15:58] jorrit at wafel dot org

When AES is used, EVP_OpenInit() will try to write the IV to allocated memory. In the current
version that memory address was set to NULL. 

I've solved the issue by introducing a new &$iv parameter which will hold the IV if an IV
cipher is used. I've also added an $iv parameter to openssl_open() to be compatible. 

Let me know if anything is missing.

Jorrit Kronjee

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=60632


--
Edit this bug report at https://bugs.php.net/bug.php?id=60632&edit=1


Thread (10 messages)

« previous php.bugs (#195803) next »