Bug #74022 [Opn]: PHP Fast CGI crashes when reading from a pfx file with valid password.
| From: | ckmailid at gmail dot com | Date: | Wed, 01 Feb 2017 13:01:58 +0000 |
| Subject: | Bug #74022 [Opn]: PHP Fast CGI crashes when reading from a pfx file with valid password. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207093@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74022&edit=1
ID: 74022
User updated by: ckmailid at gmail dot com
Reported by: ckmailid at gmail dot com
Summary: PHP Fast CGI crashes when reading from a pfx file
with valid password.
Status: Open
Type: Bug
Package: OpenSSL related
Operating System: Windows 10
PHP Version: 7.0.15
Block user comment: N
Private report: N
New Comment:
Thanks for the suggestion,
please use the following link to get the file
https://drive.google.com/file/d/0Bzazdkn-4vEOTk5VYW8wUTM1LXM/view?usp=sharing
let me know in case of any difficulties.
Previous Comments:
------------------------------------------------------------------------
[2017-02-01 12:55:10] ab@php.net
This tracker doesn't allow file uploads except patches, but that's not the case for the
purpose. If there are text files only, please gist them somewhere and post a link. Otherwise,
probably no way around than sharing them through dropbox or a similar service.
Thanks.
------------------------------------------------------------------------
[2017-02-01 06:50:10] ckmailid at gmail dot com
Hi, i generate a sample key and made a sample pfx file that can reproduce but i didn't find any
option to attach a file. I am afraid but can you please guide me where to upload sample pfx file.
------------------------------------------------------------------------
[2017-01-31 13:48:47] ab@php.net
Thanks for the report. Could you provide the backtrace? Also, were it possible to get some .pfx file
for debugging? If not your exact file, then any that reproduces.
Thanks.
------------------------------------------------------------------------
[2017-01-31 13:13:19] ckmailid at gmail dot com
Description:
------------
PHP process crashes when i use a pfx file to read using function openssl_pkcs12_read with valid
password.
But it gives error if password is wrong, that is working fine.
That pfx file is working well with openssl command line utility
Environment :
PHP : 7 .0.9
OS: windows 10
Server: IIS, Using Fast CGI
certificate : It is specially exported certificate from windows. when a highly secure certificate is
exported , it asks for login user password, and after 4 attempt with wrong password it export the
certificate even after wrong password.
You can do it by import a pfx file that with enabling strong private key encrypting checkbox on
wizard and after finish set security level HIGH.
I tried it on linux with gdb, it shows Segmentation fault (core dumped).
Test script:
---------------
if (!$cert_store = file_get_contents("sample_export.pfx")) {
echo "Error: Unable to read the cert file\n";
exit;
}
if (openssl_pkcs12_read($cert_store, $cert_info, "csos")) {
echo "Certificate Information\n";
print_r($cert_info);
} else {
echo "Error: Unable to read the cert store.\n";
exit;
}
Expected result:
----------------
it will crash the PHP process.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74022&edit=1