Bug #72535 [Fbk->Opn]: arcfour encryption stream filter crashes php

From: Date: Mon, 04 Jul 2016 19:28:30 +0000
Subject: Bug #72535 [Fbk->Opn]: arcfour encryption stream filter crashes php
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202051@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72535&edit=1 ID: 72535 Updated by: cmb@php.net Reported by: terrafrost at gmail dot com Summary: arcfour encryption stream filter crashes php -Status: Feedback +Status: Open Type: Bug Package: Reproducible crash Operating System: * PHP Version: 7.0.8 Block user comment: N Private report: N New Comment: I've got the following backtrace with a recent master (421cc65) and an x86 build (apparently the crash doesn't happen with x64 builds): php7ts_debug.dll!php_stream_bucket_unlink(_php_stream_bucket * bucket) Line 225 php7ts_debug.dll!_php_stream_write_filtered(_php_stream * stream, const char * buf, unsigned int count, int flags) Line 1186 php7ts_debug.dll!_php_stream_write(_php_stream * stream, const char * buf, unsigned int count) Line 1229 php7ts_debug.dll!zif_fwrite(_zend_execute_data * execute_data, _zval_struct * return_value) Line 1214 php7ts_debug.dll!ZEND_DO_ICALL_SPEC_RETVAL_UNUSED_HANDLER(_zend_execute_data * execute_data) Line 632 php7ts_debug.dll!execute_ex(_zend_execute_data * ex) Line 432 php7ts_debug.dll!zend_execute(_zend_op_array * op_array, _zval_struct * return_value) Line 474 php7ts_debug.dll!zend_execute_scripts(int type, _zval_struct * retval, int file_count, ...) Line 1441 php7ts_debug.dll!php_execute_script(_zend_file_handle * primary_file) Line 2532 php.exe!do_cli(int argc, char * * argv) Line 990 php.exe!main(int argc, char * * argv) Line 1378 [External Code] [Frames below may be incorrect and/or missing, no symbols loaded for kernel32.dll] Previous Comments: ------------------------------------------------------------------------ [2016-07-04 02:50:20] kalle@php.net Thank you for this bug report. To properly diagnose the problem, we need a backtrace to see what is happening behind the scenes. To find out how to generate a backtrace, please read http://bugs.php.net/bugs-generating-backtrace.php for *NIX and http://bugs.php.net/bugs-generating-backtrace-win32.php for Win32 Once you have generated a backtrace, please submit it to this bug report and change the status back to "Open". Thank you for helping us make PHP better. ------------------------------------------------------------------------ [2016-07-03 13:07:20] cmb@php.net I can reproduce the crash with PHP 5.6.23, PHP 7.0.8 and PHP 7.1.0alpha2 on Windows. A debug build of current master on Linux reports 2 memory leaks. ------------------------------------------------------------------------ [2016-07-03 05:55:29] terrafrost at gmail dot com Description: ------------ I don't think encryption filters are a very well known feature of mcrypt but none-the-less they are a feature: http://php.net/manual/en/filters.encryption.php The example in the PHP docs (with tripledes) works but arcfour does not work - you try to run it and you get a segfault. Test script: --------------- <?php $passphrase = 'My secret'; $plaintext = 'Secret secret secret data'; $iv = substr(md5('iv' . $passphrase, true), 0, 8); $key = substr(md5('pass1' . $passphrase, true) . md5('pass2' . $passphrase, true), 0, 24); $opts = array('iv' => $iv, 'key' => $key, 'mode' => 'stream'); $expected = substr($plaintext . $plaintext, 0, 48); $fp = fopen('php://memory', 'wb+'); stream_filter_append($fp, 'mcrypt.arcfour', STREAM_FILTER_WRITE, $opts); fwrite($fp, $plaintext); Expected result: ---------------- The script to actually run Actual result: -------------- The script crashes ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=72535&edit=1

« previous php.bugs (#202051) next »