Bug #72336 [NEW]: openssl_pkey_new does not properly fail with ivalid DSA params
From: bukka@php.net
Operating system: Unrelated
PHP version: 5.6.22
Package: OpenSSL related
Bug Type: Bug
Bug description:openssl_pkey_new does not properly fail with ivalid DSA params
Description:
------------
There is an issue with failing openssl_pkey_new when DSA is invalid. The
example below doesn't use bin2hex which means that the keys are invalid.
However due to bug in OpenSSL the function creates a new key that
however doesn't have a private part. The reason is that DSA_generate_key
doesn't fail because the BN_mod_exp can also return -1 which is not
checked.
Test script:
---------------
<?php
$p = '00f8000ae45b2dacb47dd977d58b719d097bdf07cb2c17660ad898518c08' .
'1a61659a16daadfaa406a0a994c743df5eda07e36bd0adcad921b77432ff' .
'24ccc31e782d647e66768122b578857e9293df78387dc8b44af2a4a3f305' .
'1f236b1000a3e31da489c6681b0031f7ec37c2e1091bdb698e7660f135b6' .
'996def90090303b7ad';
$q = '009b3734fc9f7a4a9d6437ec314e0a78c2889af64b';
$g = '00b320300a0bc55b8f0ec6edc218e2185250f38fbb8291db8a89227f6e41' .
'00d47d6ccb9c7d42fc43280ecc2ed386e81ff65bc5d6a2ae78db7372f5dc' .
'f780f4558e7ed3dd0c96a1b40727ac56c5165aed700a3b63997893a1fb21' .
'4e882221f0dd9604820dc34e2725dd6901c93e0ca56f6d76d495c332edc5' .
'b81747c4c447a941f3';
openssl_pkey_new(array('dsa' => array('p' => $p, 'q' => $q,
'g' =>
$g)));
var_dump($dsa === false);
Expected result:
----------------
bool(false)
Actual result:
--------------
bool(true)
--
Edit bug report at https://bugs.php.net/bug.php?id=72336&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=72336&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=72336&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=72336&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=72336&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=72336&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=72336&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=72336&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=72336&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=72336&r=support
Expected behavior: https://bugs.php.net/fix.php?id=72336&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=72336&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=72336&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=72336&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=72336&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=72336&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=72336&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=72336&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=72336&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=72336&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=72336&r=mysqlcfg
Thread (5 messages)
- bukka@php.net