Bug #73058 [Opn->Ver]: crypt broken when salt is 'too' long

From: Date: Fri, 09 Sep 2016 14:23:36 +0000
Subject: Bug #73058 [Opn->Ver]: crypt broken when salt is 'too' long
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-203922@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73058&edit=1 ID: 73058 Updated by: requinix@php.net Reported by: sjon at hortensius dot net Summary: crypt broken when salt is 'too' long -Status: Open +Status: Verified Type: Bug Package: hash related PHP Version: 7.1.0RC1 -Assigned To: +Assigned To: ab Block user comment: N Private report: N New Comment: Looks like it was caused by the fix for bug #72703. https://github.com/php/php-src/commit/295303b59059536079caf68b4d76acf2149bd42c Previous Comments: ------------------------------------------------------------------------ [2016-09-09 13:35:07] sjon at hortensius dot net Description: ------------ $pass = 'secret'; $salt = '$2y$07$usesomesillystringforsalt$'; var_dump(crypt($pass, $salt)); * as demonstrated on https://3v4l.org/kuAJO Test script: --------------- * works with shorter salt: https://3v4l.org/O654F * fails with longer salt: https://3v4l.org/dvgnq (includes CRYPT_SALT_LENGTH) Expected result: ---------------- string(60) "$2y$07$usesomesillystringforex.u2VJUMLRWaJNuw0Hu2FvCEimdeYVO" Actual result: -------------- string(2) "*0" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73058&edit=1

« previous php.bugs (#203922) next »