Bug #74022 [NEW]: PHP Fast CGI crashes when reading from a pfx file with valid password.
| From: | ckmailid at gmail dot com | Date: | Tue, 31 Jan 2017 13:13:24 +0000 |
| Subject: | Bug #74022 [NEW]: PHP Fast CGI crashes when reading from a pfx file with valid password. | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-207068@lists.php.net to get a copy of this message | ||
From: ckmailid at gmail dot com
Operating system: Windows 10
PHP version: 7.0.15
Package: OpenSSL related
Bug Type: Bug
Bug description:PHP Fast CGI crashes when reading from a pfx file with valid password.
Description:
------------
PHP process crashes when i use a pfx file to read using function
openssl_pkcs12_read with valid password.
But it gives error if password is wrong, that is working fine.
That pfx file is working well with openssl command line utility
Environment :
PHP : 7 .0.9
OS: windows 10
Server: IIS, Using Fast CGI
certificate : It is specially exported certificate from windows. when a
highly secure certificate is exported , it asks for login user password,
and after 4 attempt with wrong password it export the certificate even
after wrong password.
You can do it by import a pfx file that with enabling strong private key
encrypting checkbox on wizard and after finish set security level HIGH.
I tried it on linux with gdb, it shows Segmentation fault (core
dumped).
Test script:
---------------
if (!$cert_store = file_get_contents("sample_export.pfx")) {
echo "Error: Unable to read the cert file\n";
exit;
}
if (openssl_pkcs12_read($cert_store, $cert_info, "csos")) {
echo "Certificate Information\n";
print_r($cert_info);
} else {
echo "Error: Unable to read the cert store.\n";
exit;
}
Expected result:
----------------
it will crash the PHP process.
--
Edit bug report at https://bugs.php.net/bug.php?id=74022&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74022&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74022&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74022&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74022&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74022&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74022&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74022&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74022&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74022&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74022&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74022&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74022&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74022&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74022&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74022&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74022&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74022&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74022&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74022&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74022&r=mysqlcfg