Bug #72336 [NEW]: openssl_pkey_new does not properly fail with ivalid DSA params

From: Date: Sun, 05 Jun 2016 14:44:55 +0000
Subject: Bug #72336 [NEW]: openssl_pkey_new does not properly fail with ivalid DSA params
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201458@lists.php.net to get a copy of this message
From:             bukka@php.net
Operating system: Unrelated
PHP version:      5.6.22
Package:          OpenSSL related
Bug Type:         Bug
Bug description:openssl_pkey_new does not properly fail with ivalid DSA params

Description:
------------
There is an issue with failing openssl_pkey_new when DSA is invalid. The
example below doesn't use bin2hex which means that the keys are invalid.
However due to bug in OpenSSL the function creates a new key that
however doesn't have a private part. The reason is that DSA_generate_key
doesn't fail because the BN_mod_exp can also return -1 which is not
checked.

Test script:
---------------
<?php
$p = '00f8000ae45b2dacb47dd977d58b719d097bdf07cb2c17660ad898518c08' .
	'1a61659a16daadfaa406a0a994c743df5eda07e36bd0adcad921b77432ff' .
	'24ccc31e782d647e66768122b578857e9293df78387dc8b44af2a4a3f305' .
	'1f236b1000a3e31da489c6681b0031f7ec37c2e1091bdb698e7660f135b6' .
	'996def90090303b7ad';

$q = '009b3734fc9f7a4a9d6437ec314e0a78c2889af64b';

$g = '00b320300a0bc55b8f0ec6edc218e2185250f38fbb8291db8a89227f6e41' .
	'00d47d6ccb9c7d42fc43280ecc2ed386e81ff65bc5d6a2ae78db7372f5dc' .
	'f780f4558e7ed3dd0c96a1b40727ac56c5165aed700a3b63997893a1fb21' .
	'4e882221f0dd9604820dc34e2725dd6901c93e0ca56f6d76d495c332edc5' .
	'b81747c4c447a941f3';

openssl_pkey_new(array('dsa' => array('p' => $p, 'q' => $q,
'g' =>
$g)));
var_dump($dsa === false);

Expected result:
----------------
bool(false)

Actual result:
--------------
bool(true)

-- 
Edit bug report at https://bugs.php.net/bug.php?id=72336&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=72336&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=72336&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=72336&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=72336&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=72336&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=72336&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=72336&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=72336&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=72336&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=72336&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=72336&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=72336&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=72336&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72336&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=72336&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=72336&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=72336&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72336&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=72336&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=72336&r=mysqlcfg



Thread (5 messages)

« previous php.bugs (#201458) next »