Bug #73978 [Asn->Csd]: openssl_decrypt triggers bug in PDO

From: Date: Wed, 25 Jan 2017 19:55:21 +0000
Subject: Bug #73978 [Asn->Csd]: openssl_decrypt triggers bug in PDO
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206953@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73978&edit=1

 ID:                 73978
 Updated by:         bukka@php.net
 Reported by:        schmittjoh at gmail dot com
 Summary:            openssl_decrypt triggers bug in PDO
-Status:             Assigned
+Status:             Closed
 Type:               Bug
 Package:            OpenSSL related
 Operating System:   Ubuntu 16.04
 PHP Version:        7.1.1
 Assigned To:        bukka
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of bukka
Revision: http://git.php.net/?p=php-src.git;a=commit;h=519b0dc886aed287e5c3472df9c879186f5112c2
Log: Fix bug #73978 (openssl_decrypt triggers bug in PDO)


Previous Comments:
------------------------------------------------------------------------
[2017-01-25 07:37:58] requinix@php.net

Bug #69524 looks like the same issue.

------------------------------------------------------------------------
[2017-01-24 12:22:09] bukka@php.net

Looks like I missed this one (meaning forgot to add error storing in there)... Will fix it as soon
as I get chance. If you want to fix it before it's released just call openssl_error_string()
after openssl_decrypt which will move errors from the error queue.

Btw. the reason for that that you pass key ($password) with size different that key lenght (for
AES-256 it's 256bit = 32 bytes) which is either fill with zero bytes (if shorter) or trimmed
(if longer) so you can also fix it by passing correct key... ;)

------------------------------------------------------------------------
[2017-01-23 17:09:34] dz at heroku dot com

Interesting; does this also happen with 7.0?

------------------------------------------------------------------------
[2017-01-23 12:01:35] schmittjoh at gmail dot com

If you run openssl_decrypt before the connection is created, the queries run through fine.

------------------------------------------------------------------------
[2017-01-23 11:48:48] requinix@php.net

What happens if you do the problematic openssl_decrypt() *before* the connection?

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=73978


--
Edit this bug report at https://bugs.php.net/bug.php?id=73978&edit=1


Thread (9 messages)

« previous php.bugs (#206953) next »