Bug #73978 [Asn]: openssl_decrypt triggers bug in PDO

From: Date: Wed, 25 Jan 2017 07:37:59 +0000
Subject: Bug #73978 [Asn]: openssl_decrypt triggers bug in PDO
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206931@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73978&edit=1 ID: 73978 Updated by: requinix@php.net Reported by: schmittjoh at gmail dot com Summary: openssl_decrypt triggers bug in PDO Status: Assigned Type: Bug Package: OpenSSL related Operating System: Ubuntu 16.04 PHP Version: 7.1.1 Assigned To: bukka Block user comment: N Private report: N New Comment: Bug #69524 looks like the same issue. Previous Comments: ------------------------------------------------------------------------ [2017-01-24 12:22:09] bukka@php.net Looks like I missed this one (meaning forgot to add error storing in there)... Will fix it as soon as I get chance. If you want to fix it before it's released just call openssl_error_string() after openssl_decrypt which will move errors from the error queue. Btw. the reason for that that you pass key ($password) with size different that key lenght (for AES-256 it's 256bit = 32 bytes) which is either fill with zero bytes (if shorter) or trimmed (if longer) so you can also fix it by passing correct key... ;) ------------------------------------------------------------------------ [2017-01-23 17:09:34] dz at heroku dot com Interesting; does this also happen with 7.0? ------------------------------------------------------------------------ [2017-01-23 12:01:35] schmittjoh at gmail dot com If you run openssl_decrypt before the connection is created, the queries run through fine. ------------------------------------------------------------------------ [2017-01-23 11:48:48] requinix@php.net What happens if you do the problematic openssl_decrypt() *before* the connection? ------------------------------------------------------------------------ [2017-01-23 11:43:54] schmittjoh at gmail dot com Description: ------------ We get an SSL error when connecting to a secure MySQL server for some queries: Warning: PDOStatement::execute(): SSL operation failed with code 1. OpenSSL Error messages: error:0607A082:digital envelope routines:EVP_CIPHER_CTX_set_key_length:invalid key length error:0607A082:digital envelope routines:EVP_CIPHER_CTX_set_key_length:invalid key length The error happens for the next query after we used the openssl_decrypt function in our code. It seems like this function is not properly encapsulated or leaves some state behind which then triggers the error in PDO. I was not able to reproduce a test-case with values that would not expose our secret, but making a second call to openssl_decrypt with no meaningful values fixes it. Test script: --------------- // This query runs fine. $con->prepare("SELECT 1")->execute()->fetchColumn(); // This call leaves some state behind that causes error on second query. openssl_decrypt(/* real arguments here */); // Adding a call like this works around the bug. // openssl_decrypt('', 'AES-256-CBC', '', 0, ''); // Error on this query. $con->prepare("SELECT 1")->execute()->fetchColumn(); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73978&edit=1

« previous php.bugs (#206931) next »