Bug #73978 [Fbk->Asn]: openssl_decrypt triggers bug in PDO
| From: | bukka@php.net | Date: | Tue, 24 Jan 2017 12:22:14 +0000 |
| Subject: | Bug #73978 [Fbk->Asn]: openssl_decrypt triggers bug in PDO | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206913@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73978&edit=1
ID: 73978
Updated by: bukka@php.net
Reported by: schmittjoh at gmail dot com
Summary: openssl_decrypt triggers bug in PDO
-Status: Feedback
+Status: Assigned
Type: Bug
Package: PDO MySQL
Operating System: Ubuntu 16.04
PHP Version: 7.1.1
-Assigned To:
+Assigned To: bukka
Block user comment: N
Private report: N
New Comment:
Looks like I missed this one (meaning forgot to add error storing in there)... Will fix it as soon
as I get chance. If you want to fix it before it's released just call openssl_error_string()
after openssl_decrypt which will move errors from the error queue.
Btw. the reason for that that you pass key ($password) with size different that key lenght (for
AES-256 it's 256bit = 32 bytes) which is either fill with zero bytes (if shorter) or trimmed
(if longer) so you can also fix it by passing correct key... ;)
Previous Comments:
------------------------------------------------------------------------
[2017-01-23 17:09:34] dz at heroku dot com
Interesting; does this also happen with 7.0?
------------------------------------------------------------------------
[2017-01-23 12:01:35] schmittjoh at gmail dot com
If you run openssl_decrypt before the connection is created, the queries run through fine.
------------------------------------------------------------------------
[2017-01-23 11:48:48] requinix@php.net
What happens if you do the problematic openssl_decrypt() *before* the connection?
------------------------------------------------------------------------
[2017-01-23 11:43:54] schmittjoh at gmail dot com
Description:
------------
We get an SSL error when connecting to a secure MySQL server for some queries:
Warning: PDOStatement::execute(): SSL operation failed with code 1. OpenSSL Error messages:
error:0607A082:digital envelope routines:EVP_CIPHER_CTX_set_key_length:invalid key length
error:0607A082:digital envelope routines:EVP_CIPHER_CTX_set_key_length:invalid key length
The error happens for the next query after we used the openssl_decrypt function in our code. It
seems like this function is not properly encapsulated or leaves some state behind which then
triggers the error in PDO.
I was not able to reproduce a test-case with values that would not expose our secret, but making a
second call to openssl_decrypt with no meaningful values fixes it.
Test script:
---------------
// This query runs fine.
$con->prepare("SELECT 1")->execute()->fetchColumn();
// This call leaves some state behind that causes error on second query.
openssl_decrypt(/* real arguments here */);
// Adding a call like this works around the bug.
// openssl_decrypt('', 'AES-256-CBC', '', 0, '');
// Error on this query.
$con->prepare("SELECT 1")->execute()->fetchColumn();
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73978&edit=1