Bug #70752 [Com]: Depacking with wrong password leaves 0 length files
| From: | nhojohl at gmail dot com | Date: | Tue, 17 Nov 2015 02:41:11 +0000 |
| Subject: | Bug #70752 [Com]: Depacking with wrong password leaves 0 length files | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197291@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70752&edit=1
ID: 70752
Comment by: nhojohl at gmail dot com
Reported by: furun at arcor dot de
Summary: Depacking with wrong password leaves 0 length files
Status: Open
Type: Bug
Package: Zip Related
Operating System: all
PHP Version: 5.6.14
Block user comment: N
Private report: N
New Comment:
Do you have a test script that replicates the behavior? I just test it and it worked without any
issues.
Thanks!
Previous Comments:
------------------------------------------------------------------------
[2015-10-20 20:26:49] furun at arcor dot de
Description:
------------
---
From manual page: http://www.php.net/ziparchive.setpassword
---
If a file is de-packed with ZipArchive::setPassword, and the password is wrong, it leafs a file with
0 length. In case a file exist already with the same name like the unpacked one, this file will be
overwritten with 0 length content.
This behavior is unclean. In case a password is wrong, no files should be created or changed.
For Example:
If ZipArchive is used to update content in a secure way, a wrong password would destroy the existing
files. Exactly what the password protection of the updater file should avoid.
And, There is no way to check a password before using it (... i guess)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70752&edit=1