Bug #71929 [Opn->Ver]: Certification information (CERTINFO) data parsing error

From: Date: Sun, 24 Apr 2016 00:49:09 +0000
Subject: Bug #71929 [Opn->Ver]: Certification information (CERTINFO) data parsing error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200724@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71929&edit=1

 ID:                 71929
 Updated by:         pierrick@php.net
 Reported by:        asmqb7 at gmail dot com
 Summary:            Certification information (CERTINFO) data parsing
                     error
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            cURL related
 Operating System:   Linux (Arch Linux)
 PHP Version:        7.0.4
-Assigned To:        
+Assigned To:        pajoye
 Block user comment: N
 Private report:     N

 New Comment:

Thanks for reporting the bug. I'm assigning this to the initial commiter to see what he's
thinking about it because I have no clue if we should fix it or not since the bug was introduced in
the first version in 5.3.


Previous Comments:
------------------------------------------------------------------------
[2016-03-31 06:18:23] asmqb7 at gmail dot com

Description:
------------
As demonstrated in "Actual Result," the cURL PHP library appears to be mis-parsing the
Subject and Issuer lines of the TLS certification information.

According to https://curl.haxx.se/libcurl/c/CURLINFO_CERTINFO.html

> The info chain is provided in a series of data in the format "name:content" where the
> content is for the specific named data.

The above URL references certinfo.c, which can be found at https://curl.haxx.se/libcurl/c/certinfo.html
(the "Download raw" link toward the top currently points to https://raw.githubusercontent.com/curl/curl/master/docs/examples/certinfo.c).

This is a turnkey certificate demo that connects to https://example.com/ and displays the certificate(s) it gets back.
For easy copy-pasting:

wget https://raw.githubusercontent.com/curl/curl/master/docs/examples/certinfo.c
cat certinfo.c; read  # trust but verify
gcc -o certinfo certinfo.c -lcurl
./certinfo

The PHP test script attached to this bug similarly connects to https://example.com/ with CURLOPT_CERTINFO set to TRUE, then
print_r()s the contents of curl_getinfo(), which contains the retrieved certificate info. The
relevant portions of the output I get on my machine can be found under "Actual Results".

I've tested this on PHP 7.0.4 as noted, but not any other versions. This option appears to have
been committed in 2009 (https://bugs.php.net/bug.php?id=49253); it may be interesting to test in PHP
versions from that point.

I'm reporting this as a bug and not a security issue as I do not consider it remotely
exploitable and most (all?) developers would have noticed the anomaly in the development process.

Considering the above, however, I'm not sure if fixing this would break poorly written
workarounds :( especially if this is a long-term bug and not a recent regression.

Test script:
---------------
<?php

$ch = curl_init();

curl_setopt_array($ch, [
	CURLOPT_CERTINFO => true,
	CURLOPT_URL => "https://example.com/",
	CURLOPT_RETURNTRANSFER => true
]);

curl_exec($ch);

print_r(curl_getinfo($ch));

?>


Actual result:
--------------
Irrelevant data removed; a small amount of context left in for comparison.

Output of certinfo.c:

...
Subject:C = US, ST = California, L = Los Angeles, O = Internet Corporation for Assigned Names and
Numbers, OU = Technology, CN = www.example.org
Issuer:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert SHA2 High Assurance Server CA
Version:2
Serial Number:0e64c5fbc236ade14b172aeb41c78cb0
Signature Algorithm:sha256WithRSAEncryption
Public Key Algorithm:rsaEncryption
...
Subject:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert SHA2 High Assurance Server CA
Issuer:C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert High Assurance EV Root CA
Version:2
Serial Number:04e1e7a4dc5cf2f36dc02b42b85d159f
Signature Algorithm:sha256WithRSAEncryption
Public Key Algorithm:rsaEncryption
...


Output of PHP script:

  [certinfo] => Array
        (
            [0] => Array
                (
                    [Subject] => Array
                        (
                            [C ] =>  US, ST = California, L = Los Angeles, O = Internet
Corporation for Assigned Names and Numbers, OU = Technology, CN = www.example.org
                        )

                    [Issuer] => Array
                        (
                            [C ] =>  US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert
SHA2 High Assurance Server CA
                        )

                    [Version] => 2
                    [Serial Number] => 0e64c5fbc236ade14b172aeb41c78cb0
                    [Signature Algorithm] => sha256WithRSAEncryption
                    [Public Key Algorithm] => rsaEncryption
                    ...
       )
       [1] => Array
                (
                    [Subject] => Array
                        (
                            [C ] =>  US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert
SHA2 High Assurance Server CA
                        )

                    [Issuer] => Array
                        (
                            [C ] =>  US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert
High Assurance EV Root CA
                        )

                    [Version] => 2
                    [Serial Number] => 04e1e7a4dc5cf2f36dc02b42b85d159f
                    [Signature Algorithm] => sha256WithRSAEncryption
                    [Public Key Algorithm] => rsaEncryption
                    ...
                )
        )
)


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71929&edit=1


Thread (8 messages)

« previous php.bugs (#200724) next »