Bug #71506 [Asn]: inflate_add() does not detect corrupted compressed data
| From: | cmb@php.net | Date: | Mon, 01 Aug 2016 13:49:36 +0000 |
| Subject: | Bug #71506 [Asn]: inflate_add() does not detect corrupted compressed data | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202802@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71506&edit=1
ID: 71506
Updated by: cmb@php.net
Reported by: salsi at icosaedro dot it
Summary: inflate_add() does not detect corrupted compressed
data
Status: Assigned
Type: Bug
Package: Zlib related
Operating System: Slackware 14.1
PHP Version: Irrelevant
-Assigned To: rdlowrey
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> It might be necessary to add something like inflate_close() [â¦]
Ah, there is alread ZLIB_FINISH; should have read the report more
carefully. Will have a look at this issue.
Previous Comments:
------------------------------------------------------------------------
[2016-08-01 13:38:37] cmb@php.net
It might be necessary to add something like inflate_close() to
detect the end of the input, so the data could be verified.
------------------------------------------------------------------------
[2016-02-03 10:54:24] salsi at icosaedro dot it
Description:
------------
The inflate_add() function is available as of PHP 7.0.0 and it incrementally decompresses DEFLATE,
ZLIB and GZIP compressed data passed chunk by chunk. When GZIP compressed data are feed to this
function, it succeeds detecting corrupted data, but it fails to detect trunked data, as the
following test script proves.
Test script:
---------------
<?php
error_reporting(-1);
// $deflateContext = deflate_init(ZLIB_ENCODING_GZIP);
// $compressed = deflate_add($deflateContext, "Data to compress", ZLIB_NO_FLUSH);
// $compressed .= deflate_add($deflateContext, ", more data", ZLIB_NO_FLUSH);
// $compressed .= deflate_add($deflateContext, ", and even more data!", ZLIB_FINISH);
// Creates GZIP compressed data:
$plain = "Data to compress, more data, and even more data!";
$compressed = gzencode($plain);
echo "Compressed: ", wordwrap(bin2hex($compressed), 2, " ", TRUE),
"\n";
// These tests succeeded with error, as expected:
// Invalid checksum:
// $compressed[strlen($compressed)-5] = 'x';
// --> E_WARNING: inflate_add(): data error
// Invalid length:
// $compressed[strlen($compressed)-2] = 'x';
// --> E_WARNING: inflate_add(): data error
// Corrupted compressed data:
// $compressed[strlen($compressed)/2] = 'x';
// --> E_WARNING: inflate_add(): data error
// Following test FAILED to detect corrupted data:
// Trunked lenght field:
// $compressed = substr($compressed, 0, strlen($compressed)-4);
// --> Data to compress, more data, and even more data!
// NO ERROR SIGNALED
// Trunked Adler32 and lenght fields:
// $compressed = substr($compressed, 0, strlen($compressed)-8);
// --> Data to compress, more data, and even more data!
// NO ERROR SIGNALED
// Trunked some data, Adler32 and lenght fields:
$compressed = substr($compressed, 0, strlen($compressed)-12);
// --> Data to compress, more data, and eve
// TRUNKED RESULTING DATA, NO ERROR SIGNALED
echo "Corrupted : ", wordwrap(bin2hex($compressed), 2, " ", TRUE),
"\n";
$inflateContext = inflate_init(ZLIB_ENCODING_GZIP);
$uncompressed = inflate_add($inflateContext, $compressed, ZLIB_NO_FLUSH);
$uncompressed .= inflate_add($inflateContext, NULL, ZLIB_FINISH);
echo $uncompressed;
?>
Expected result:
----------------
E_WARNING: inflate_add(): data error
Actual result:
--------------
Data to compress, more data, and eve
(note how the original plain string has been trunked, but no error is detected).
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71506&edit=1