From: asmqb7 at gmail dot com
Operating system: Linux (Arch Linux)
PHP version: 7.0.4
Package: cURL related
Bug Type: Bug
Bug description:Certification information (CERTINFO) data parsing error
Description:
------------
As demonstrated in "Actual Result," the cURL PHP library appears to be
mis-parsing the Subject and Issuer lines of the TLS certification
information.
According to https://curl.haxx.se/libcurl/c/CURLINFO_CERTINFO.html
> The info chain is provided in a series of data in the format
"name:content" where the content is for the specific named data.
The above URL references certinfo.c, which can be found at
https://curl.haxx.se/libcurl/c/certinfo.html
(the "Download raw" link
toward the top currently points to
https://raw.githubusercontent.com/curl/curl/master/docs/examples/certinfo.c).
This is a turnkey certificate demo that connects to https://example.com/
and displays the certificate(s) it gets back. For easy copy-pasting:
wget
https://raw.githubusercontent.com/curl/curl/master/docs/examples/certinfo.c
cat certinfo.c; read # trust but verify
gcc -o certinfo certinfo.c -lcurl
./certinfo
The PHP test script attached to this bug similarly connects to
https://example.com/ with CURLOPT_CERTINFO set to TRUE, then
print_r()s
the contents of curl_getinfo(), which contains the retrieved certificate
info. The relevant portions of the output I get on my machine can be
found under "Actual Results".
I've tested this on PHP 7.0.4 as noted, but not any other versions. This
option appears to have been committed in 2009
(https://bugs.php.net/bug.php?id=49253); it may be interesting to test
in PHP versions from that point.
I'm reporting this as a bug and not a security issue as I do not
consider it remotely exploitable and most (all?) developers would have
noticed the anomaly in the development process.
Considering the above, however, I'm not sure if fixing this would break
poorly written workarounds :( especially if this is a long-term bug and
not a recent regression.
Test script:
---------------
<?php
$ch = curl_init();
curl_setopt_array($ch, [
CURLOPT_CERTINFO => true,
CURLOPT_URL => "https://example.com/",
CURLOPT_RETURNTRANSFER => true
]);
curl_exec($ch);
print_r(curl_getinfo($ch));
?>
Actual result:
--------------
Irrelevant data removed; a small amount of context left in for
comparison.
Output of certinfo.c:
...
Subject:C = US, ST = California, L = Los Angeles, O = Internet
Corporation for Assigned Names and Numbers, OU = Technology, CN =
www.example.org
Issuer:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert
SHA2 High Assurance Server CA
Version:2
Serial Number:0e64c5fbc236ade14b172aeb41c78cb0
Signature Algorithm:sha256WithRSAEncryption
Public Key Algorithm:rsaEncryption
...
Subject:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert
SHA2 High Assurance Server CA
Issuer:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert
High Assurance EV Root CA
Version:2
Serial Number:04e1e7a4dc5cf2f36dc02b42b85d159f
Signature Algorithm:sha256WithRSAEncryption
Public Key Algorithm:rsaEncryption
...
Output of PHP script:
[certinfo] => Array
(
[0] => Array
(
[Subject] => Array
(
[C ] => US, ST = California, L = Los
Angeles, O = Internet Corporation for Assigned Names and Numbers, OU =
Technology, CN = www.example.org
)
[Issuer] => Array
(
[C ] => US, O = DigiCert Inc, OU =
www.digicert.com, CN = DigiCert SHA2 High Assurance Server CA
)
[Version] => 2
[Serial Number] => 0e64c5fbc236ade14b172aeb41c78cb0
[Signature Algorithm] => sha256WithRSAEncryption
[Public Key Algorithm] => rsaEncryption
...
)
[1] => Array
(
[Subject] => Array
(
[C ] => US, O = DigiCert Inc, OU =
www.digicert.com, CN = DigiCert SHA2 High Assurance Server CA
)
[Issuer] => Array
(
[C ] => US, O = DigiCert Inc, OU =
www.digicert.com, CN = DigiCert High Assurance EV Root CA
)
[Version] => 2
[Serial Number] => 04e1e7a4dc5cf2f36dc02b42b85d159f
[Signature Algorithm] => sha256WithRSAEncryption
[Public Key Algorithm] => rsaEncryption
...
)
)
)
--
Edit bug report at https://bugs.php.net/bug.php?id=71929&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71929&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71929&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71929&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71929&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71929&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71929&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71929&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71929&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71929&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71929&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71929&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71929&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71929&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71929&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71929&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71929&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71929&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71929&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71929&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71929&r=mysqlcfg