Bug #70752 [Com]: Depacking with wrong password leaves 0 length files
| From: | furun at arcor dot de | Date: | Tue, 17 Nov 2015 20:59:54 +0000 |
| Subject: | Bug #70752 [Com]: Depacking with wrong password leaves 0 length files | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197305@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70752&edit=1
ID: 70752
Comment by: furun at arcor dot de
Reported by: furun at arcor dot de
Summary: Depacking with wrong password leaves 0 length files
Status: Open
Type: Bug
Package: Zip Related
Operating System: all
PHP Version: 5.6.14
Block user comment: N
Private report: N
New Comment:
Thanks for the reply.
Sorry for the missing test code.
For testing:
1. Create a ZIP file like "C:\Temp\Test.zip",
with a file inside like "Test.txt",
with a password encrypted like "pass".
2. Run the test-code Zip_Test().
3. The password is wrong, and you should have a file named "Test.txt" with the length 0 in
"C:\Temp\".
4. It create the 'ERROR: extractTo' Error.
5. If "C:\Temp\Test.txt" already exists and has content, it will be overwritten.
tested on xampp, PHP Version 5.6.3, on windows 7
<?php
Zip_Test();
function Zip_Test () {
$filePath = 'C:\\Temp\\Test.zip';
$destinationDirectory = 'C:\\Temp\\';
$password = 'pass_wrong';
$zip = new ZipArchive;
if ($zip->open($filePath) !== true) { print ('ERROR: open'); return;
}
if ($zip->setPassword($password) !== true) { print ('ERROR: setPassword');
return; }
if ($zip->extractTo($destinationDirectory) !== true) { print ('ERROR: extractTo');
return; }
$zip->close();
}
Previous Comments:
------------------------------------------------------------------------
[2015-11-17 02:41:10] nhojohl at gmail dot com
Do you have a test script that replicates the behavior? I just test it and it worked without any
issues.
Thanks!
------------------------------------------------------------------------
[2015-10-20 20:26:49] furun at arcor dot de
Description:
------------
---
From manual page: http://www.php.net/ziparchive.setpassword
---
If a file is de-packed with ZipArchive::setPassword, and the password is wrong, it leafs a file with
0 length. In case a file exist already with the same name like the unpacked one, this file will be
overwritten with 0 length content.
This behavior is unclean. In case a password is wrong, no files should be created or changed.
For Example:
If ZipArchive is used to update content in a secure way, a wrong password would destroy the existing
files. Exactly what the password protection of the updater file should avoid.
And, There is no way to check a password before using it (... i guess)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70752&edit=1