Bug #70625 [Opn->Csd]: mcrypt_encrypt() : won't return data when no IV was specified under RC4.
| From: | nikic@php.net | Date: | Sat, 03 Oct 2015 08:15:00 +0000 |
| Subject: | Bug #70625 [Opn->Csd]: mcrypt_encrypt() : won't return data when no IV was specified under RC4. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-196362@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70625&edit=1
ID: 70625
Updated by: nikic@php.net
Reported by: jparedes at gmail dot com
Summary: mcrypt_encrypt() : won't return data when no IV was
specified under RC4.
-Status: Open
+Status: Closed
Type: Bug
Package: mcrypt related
Operating System: Linux
PHP Version: 5.6
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nikic
Revision: http://git.php.net/?p=php-src.git;a=commit;h=fe1933aae2185624bd51b1fd46b8d959f88daf4a
Log: Fixed bug #70625
Previous Comments:
------------------------------------------------------------------------
[2015-10-02 20:29:40] nikic@php.net
The issue here is that mcrypt_enc_mode_has_iv() reports on a property of the mode only, and reports
the stream cipher mode to have an IV, regardless of used cipher. mcrypt_enc_get_iv_size() returns a
property of the cipher, in this case 0, which seems to be the signal for "doesn't actually
need an IV, even if mode_has_iv() says so". So we should add an additional check for 0 expected
IV size.
------------------------------------------------------------------------
[2015-10-02 20:17:22] jparedes at gmail dot com
unintentionally changed affected php version while editing in parallel. Reverting.
------------------------------------------------------------------------
[2015-10-02 20:13:32] jparedes at gmail dot com
I correct myself, issue seems to arise after this commit 25d801f [1], because -if i'm not
wrong- it's assumes RC4 encmode should have IV and it fact it should not.
[1] https://github.com/php/php-src/commit/25d801f97ec3f4bcac8977efd50f843eba9b19e1
------------------------------------------------------------------------
[2015-10-02 20:12:38] nikic@php.net
This is due to the additional IV validation in PHP 5.6: https://3v4l.org/af8oG
Probably some special handling for stream ciphers is missing.
------------------------------------------------------------------------
[2015-10-02 19:41:57] jparedes at gmail dot com
Apparently the introduction of zpp checks [1]is in effect what causes the difference in the desired
behaviour. This emerged in php-7.0.0beta3.
[1] https://github.com/php/php-src/commit/d8ed84e4c4d0bd0bac88d2c0ed6e072a7d7ea49d
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70625
--
Edit this bug report at https://bugs.php.net/bug.php?id=70625&edit=1