Bug #70752 [Com]: Depacking with wrong password leaves 0 length files

From: Date: Tue, 17 Nov 2015 02:41:11 +0000
Subject: Bug #70752 [Com]: Depacking with wrong password leaves 0 length files
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197291@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70752&edit=1 ID: 70752 Comment by: nhojohl at gmail dot com Reported by: furun at arcor dot de Summary: Depacking with wrong password leaves 0 length files Status: Open Type: Bug Package: Zip Related Operating System: all PHP Version: 5.6.14 Block user comment: N Private report: N New Comment: Do you have a test script that replicates the behavior? I just test it and it worked without any issues. Thanks! Previous Comments: ------------------------------------------------------------------------ [2015-10-20 20:26:49] furun at arcor dot de Description: ------------ --- From manual page: http://www.php.net/ziparchive.setpassword --- If a file is de-packed with ZipArchive::setPassword, and the password is wrong, it leafs a file with 0 length. In case a file exist already with the same name like the unpacked one, this file will be overwritten with 0 length content. This behavior is unclean. In case a password is wrong, no files should be created or changed. For Example: If ZipArchive is used to update content in a secure way, a wrong password would destroy the existing files. Exactly what the password protection of the updater file should avoid. And, There is no way to check a password before using it (... i guess) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70752&edit=1

« previous php.bugs (#197291) next »