Bug #70529 [Opn]: mcrypt_decrypt() call sometime results in "String is not zero-terminated" error
| From: | yohgaki@php.net | Date: | Fri, 18 Sep 2015 22:22:48 +0000 |
| Subject: | Bug #70529 [Opn]: mcrypt_decrypt() call sometime results in "String is not zero-terminated" error | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-196080@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70529&edit=1
ID: 70529
Updated by: yohgaki@php.net
Reported by: yohgaki@php.net
Summary: mcrypt_decrypt() call sometime results in "String is
not zero-terminated" error
Status: Open
Type: Bug
Package: mcrypt related
Operating System: Linux
PHP Version: 7.0Git-2015-09-18 (Git)
Block user comment: N
Private report: N
New Comment:
Although I don't see errors if I don't use mcrypt, session module may do something wrong
in these lines
$data = parent::read($id);
return parent::write($id, $data);
I'll look into this. Could anyone look into mcrypt?
Previous Comments:
------------------------------------------------------------------------
[2015-09-18 22:13:04] yohgaki@php.net
Description:
------------
While I was looking into this bug
https://bugs.php.net/bug.php?id=70520
I found mcrypt_decrypt() sometimes raises "String is not zero-terminated" error. It seems
mcrypt_decrypt() returns broken data sometimes also. It makes session decode fail on occasion.
Warning: String is not zero-terminated (�J?w�fr,�:v�handler) (source:
/home/yohgaki/git/oss/php.net/php-src/Zend/zend_execute.c:2061) in
/home/yohgaki/workspace/ext/git/oss/php.net/php-src/tt2.php on line 20
Warning: session_start(): Failed to decode session object. Session has been destroyed in
/home/yohgaki/workspace/ext/git/oss/php.net/php-src/tt2.php on line 38
Tested by CLI server. If I don't use mcrypt_decrypt/encrypt(), the test code will not raise
errors.
Test script:
---------------
<?php
ob_start();
error_reporting(E_ALL | E_STRICT);
ini_set('session.save_path', '/tmp');
ini_set('display_errors', true);
class EncryptedSessionHandler extends SessionHandler
{
private $key;
public function __construct($key)
{
$this->key = $key;
}
public function read($id)
{
$data = parent::read($id);
return mcrypt_decrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB);
//return $data;
}
public function write($id, $data)
{
$data = mcrypt_encrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB);
return parent::write($id, $data);
}
}
ini_set('session.save_handler', 'files');
$key = substr(sha1(random_bytes(24)), 0, 24);
$handler = new EncryptedSessionHandler($key);
session_set_save_handler($handler, true);
echo '<pre>';
session_start();
$_SESSION['key'] = 1234;
var_dump($_SESSION);
echo session_id() . PHP_EOL;
session_regenerate_id(true);
echo session_id() . PHP_EOL;
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70529&edit=1