Bug #71506 [Opn]: inflate_add() does not detect corrupted compressed data

From: Date: Mon, 01 Aug 2016 13:38:38 +0000
Subject: Bug #71506 [Opn]: inflate_add() does not detect corrupted compressed data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202801@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71506&edit=1 ID: 71506 Updated by: cmb@php.net Reported by: salsi at icosaedro dot it Summary: inflate_add() does not detect corrupted compressed data Status: Open Type: Bug Package: Zlib related Operating System: Slackware 14.1 PHP Version: Irrelevant -Assigned To: +Assigned To: rdlowrey Block user comment: N Private report: N New Comment: It might be necessary to add something like inflate_close() to detect the end of the input, so the data could be verified. Previous Comments: ------------------------------------------------------------------------ [2016-02-03 10:54:24] salsi at icosaedro dot it Description: ------------ The inflate_add() function is available as of PHP 7.0.0 and it incrementally decompresses DEFLATE, ZLIB and GZIP compressed data passed chunk by chunk. When GZIP compressed data are feed to this function, it succeeds detecting corrupted data, but it fails to detect trunked data, as the following test script proves. Test script: --------------- <?php error_reporting(-1); // $deflateContext = deflate_init(ZLIB_ENCODING_GZIP); // $compressed = deflate_add($deflateContext, "Data to compress", ZLIB_NO_FLUSH); // $compressed .= deflate_add($deflateContext, ", more data", ZLIB_NO_FLUSH); // $compressed .= deflate_add($deflateContext, ", and even more data!", ZLIB_FINISH); // Creates GZIP compressed data: $plain = "Data to compress, more data, and even more data!"; $compressed = gzencode($plain); echo "Compressed: ", wordwrap(bin2hex($compressed), 2, " ", TRUE), "\n"; // These tests succeeded with error, as expected: // Invalid checksum: // $compressed[strlen($compressed)-5] = 'x'; // --> E_WARNING: inflate_add(): data error // Invalid length: // $compressed[strlen($compressed)-2] = 'x'; // --> E_WARNING: inflate_add(): data error // Corrupted compressed data: // $compressed[strlen($compressed)/2] = 'x'; // --> E_WARNING: inflate_add(): data error // Following test FAILED to detect corrupted data: // Trunked lenght field: // $compressed = substr($compressed, 0, strlen($compressed)-4); // --> Data to compress, more data, and even more data! // NO ERROR SIGNALED // Trunked Adler32 and lenght fields: // $compressed = substr($compressed, 0, strlen($compressed)-8); // --> Data to compress, more data, and even more data! // NO ERROR SIGNALED // Trunked some data, Adler32 and lenght fields: $compressed = substr($compressed, 0, strlen($compressed)-12); // --> Data to compress, more data, and eve // TRUNKED RESULTING DATA, NO ERROR SIGNALED echo "Corrupted : ", wordwrap(bin2hex($compressed), 2, " ", TRUE), "\n"; $inflateContext = inflate_init(ZLIB_ENCODING_GZIP); $uncompressed = inflate_add($inflateContext, $compressed, ZLIB_NO_FLUSH); $uncompressed .= inflate_add($inflateContext, NULL, ZLIB_FINISH); echo $uncompressed; ?> Expected result: ---------------- E_WARNING: inflate_add(): data error Actual result: -------------- Data to compress, more data, and eve (note how the original plain string has been trunked, but no error is detected). ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=71506&edit=1

« previous php.bugs (#202801) next »