Bug #70752 [Com]: Depacking with wrong password leaves 0 length files

From: Date: Tue, 17 Nov 2015 21:30:20 +0000
Subject: Bug #70752 [Com]: Depacking with wrong password leaves 0 length files
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-197306@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70752&edit=1 ID: 70752 Comment by: furun at arcor dot de Reported by: furun at arcor dot de Summary: Depacking with wrong password leaves 0 length files Status: Open Type: Bug Package: Zip Related Operating System: all PHP Version: 5.6.14 Block user comment: N Private report: N New Comment: ps: ...The argument is, if the password is wrong, it should not create/change any files. Previous Comments: ------------------------------------------------------------------------ [2015-11-17 20:59:53] furun at arcor dot de Thanks for the reply. Sorry for the missing test code. For testing: 1. Create a ZIP file like "C:\Temp\Test.zip", with a file inside like "Test.txt", with a password encrypted like "pass". 2. Run the test-code Zip_Test(). 3. The password is wrong, and you should have a file named "Test.txt" with the length 0 in "C:\Temp\". 4. It create the 'ERROR: extractTo' Error. 5. If "C:\Temp\Test.txt" already exists and has content, it will be overwritten. tested on xampp, PHP Version 5.6.3, on windows 7 <?php Zip_Test(); function Zip_Test () { $filePath = 'C:\\Temp\\Test.zip'; $destinationDirectory = 'C:\\Temp\\'; $password = 'pass_wrong'; $zip = new ZipArchive; if ($zip->open($filePath) !== true) { print ('ERROR: open'); return; } if ($zip->setPassword($password) !== true) { print ('ERROR: setPassword'); return; } if ($zip->extractTo($destinationDirectory) !== true) { print ('ERROR: extractTo'); return; } $zip->close(); } ------------------------------------------------------------------------ [2015-11-17 02:41:10] nhojohl at gmail dot com Do you have a test script that replicates the behavior? I just test it and it worked without any issues. Thanks! ------------------------------------------------------------------------ [2015-10-20 20:26:49] furun at arcor dot de Description: ------------ --- From manual page: http://www.php.net/ziparchive.setpassword --- If a file is de-packed with ZipArchive::setPassword, and the password is wrong, it leafs a file with 0 length. In case a file exist already with the same name like the unpacked one, this file will be overwritten with 0 length content. This behavior is unclean. In case a password is wrong, no files should be created or changed. For Example: If ZipArchive is used to update content in a secure way, a wrong password would destroy the existing files. Exactly what the password protection of the updater file should avoid. And, There is no way to check a password before using it (... i guess) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70752&edit=1

« previous php.bugs (#197306) next »