Bug #71917 [NEW]: openssl_open() returns junk on envelope < 16 bytes
| From: | gelenkig at runbox dot com | Date: | Tue, 29 Mar 2016 12:19:09 +0000 |
| Subject: | Bug #71917 [NEW]: openssl_open() returns junk on envelope < 16 bytes | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-200210@lists.php.net to get a copy of this message | ||
From: gelenkig at runbox dot com
Operating system: Linux
PHP version: 5.5.33
Package: OpenSSL related
Bug Type: Bug
Bug description:openssl_open() returns junk on envelope < 16 bytes
Description:
------------
OpenSSL provides two functions: openssl_seal and openssl_open which are
basically just handy shortcuts to manually:
- generating envelope key (CS-random string)
- encrypting it with public key
- encrypting data itself with that envelope key
- storing both encrypted data and encrypted envelope
One can successfully do this manually via openssl command line tool:
i.e. encrypt envelope/data with openssl cli and unseal with PHP or vice
versa.
But PHP's openssl_open() seems to have a bug: it will return some junk
instead of decrypted plaintext if envelope's key is shorter than 16
bytes long. It will work fine if it's 16 bytes long or longer. Since
openssl_seal() generates 128-bit key it's not a high-priority problem
but at least openssl_open() should emit a warning if for whatever the
reason it's not possible to fix the behaviour.
This was confirmed on RC4 cipher (default method).
Test script:
---------------
function test($envkey) {
// $publicKey, $privateKey are OpenSSL Key resources.
openssl_public_encrypt($envkey, $envelope,
openssl_pkey_get_public($publicKey));
$sealed = openssl_encrypt('plaintext', 'rc4', $envkey,
OPENSSL_RAW_DATA);
openssl_open($sealed, $output, $envelope, $privateKey, 'rc4');
assert($output === 'plaintext');
}
// works - key of 16 bytes
test('1234567890123456');
// fails - key of 15 bytes
test('123456789012345');
Expected result:
----------------
openssl_open() should return original plaintext as long as supplied keys
are correct, regardless of the envelope key's length.
Actual result:
--------------
openssl_open() returns some junk with no warning or other indication if
data was encrypted with envelope key shorter than 16 bytes, at least if
using RC4 cipher, even when given correct keys.
--
Edit bug report at https://bugs.php.net/bug.php?id=71917&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71917&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71917&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71917&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71917&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71917&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71917&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71917&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71917&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71917&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71917&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71917&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71917&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71917&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71917&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71917&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71917&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71917&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71917&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71917&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71917&r=mysqlcfg