Bug #70752 [Opn->Ana]: Depacking with wrong password leaves 0 length files

From: Date: Mon, 05 Sep 2016 16:10:22 +0000
Subject: Bug #70752 [Opn->Ana]: Depacking with wrong password leaves 0 length files
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203809@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70752&edit=1

 ID:                 70752
 Updated by:         cmb@php.net
 Reported by:        furun at arcor dot de
 Summary:            Depacking with wrong password leaves 0 length files
-Status:             Open
+Status:             Analyzed
 Type:               Bug
 Package:            Zip Related
 Operating System:   all
 PHP Version:        5.6.14
 Block user comment: N
 Private report:     N

 New Comment:

I can confirm this issue. The problem is that libzip will only
check the password when the entry is actually opened. However, PHP
will first open the output stream, and only then call zip_fopen()[1],
so an empty file remains.

Simply changing the order (i.e. first zip_open() then
php_stream_open_wrapper()) should solve the issue.

[1] <https://github.com/php/php-src/blob/PHP-7.0.10/ext/zip/php_zip.c#L241-L253>


Previous Comments:
------------------------------------------------------------------------
[2015-11-17 21:30:19] furun at arcor dot de

ps:

...The argument is, if the password is wrong, it should not create/change any files.

------------------------------------------------------------------------
[2015-11-17 20:59:53] furun at arcor dot de

Thanks for the reply.

Sorry for the missing test code.

For testing:
1. Create a ZIP file like "C:\Temp\Test.zip", 
   with a file inside like "Test.txt", 
   with a password encrypted like "pass".
2. Run the test-code Zip_Test().
3. The password is wrong, and you should have a file named "Test.txt" with the length 0 in
"C:\Temp\".
4. It create the 'ERROR: extractTo' Error.

5. If "C:\Temp\Test.txt" already exists and has content, it will be overwritten.

tested on xampp, PHP Version 5.6.3, on windows 7



<?php

Zip_Test();

function Zip_Test () {

	$filePath = 'C:\\Temp\\Test.zip';
	$destinationDirectory = 'C:\\Temp\\';
	$password = 'pass_wrong';

	$zip = new ZipArchive;

	if ($zip->open($filePath) !== true)                  { print ('ERROR: open'); return;
}
	if ($zip->setPassword($password) !== true)           { print ('ERROR: setPassword');
return; }
	if ($zip->extractTo($destinationDirectory) !== true) { print ('ERROR: extractTo');
return; }

	$zip->close();
	
}

------------------------------------------------------------------------
[2015-11-17 02:41:10] nhojohl at gmail dot com

Do you have a test script that replicates the behavior? I just test it and it worked without any
issues.

Thanks!

------------------------------------------------------------------------
[2015-10-20 20:26:49] furun at arcor dot de

Description:
------------
---
From manual page: http://www.php.net/ziparchive.setpassword
---

If a file is de-packed with ZipArchive::setPassword, and the password is wrong, it leafs a file with
0 length. In case a file exist already with the same name like the unpacked one, this file will be
overwritten with 0 length content.

This behavior is unclean. In case a password is wrong, no files should be created or changed.

For Example:
If ZipArchive is used to update content in a secure way, a wrong password would destroy the existing
files. Exactly what the password protection of the updater file should avoid.



And, There is no way to check a password before using it (... i guess)





------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=70752&edit=1


Thread (6 messages)

« previous php.bugs (#203809) next »