Bug #74022 [Opn->Csd]: PHP Fast CGI crashes when reading from a pfx file with valid password.
| From: | ab@php.net | Date: | Thu, 02 Feb 2017 12:09:36 +0000 |
| Subject: | Bug #74022 [Opn->Csd]: PHP Fast CGI crashes when reading from a pfx file with valid password. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207117@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74022&edit=1
ID: 74022
Updated by: ab@php.net
Reported by: ckmailid at gmail dot com
Summary: PHP Fast CGI crashes when reading from a pfx file
with valid password.
-Status: Open
+Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: Windows 10
PHP Version: 7.0.15
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=6fc0ae638acd2a66a4181078f4ac5d789762d9de
Log: Fixed #74022 PHP Fast CGI crashes when reading from a pfx file.
Previous Comments:
------------------------------------------------------------------------
[2017-02-01 13:01:57] ckmailid at gmail dot com
Thanks for the suggestion,
please use the following link to get the file
https://drive.google.com/file/d/0Bzazdkn-4vEOTk5VYW8wUTM1LXM/view?usp=sharing
let me know in case of any difficulties.
------------------------------------------------------------------------
[2017-02-01 12:55:10] ab@php.net
This tracker doesn't allow file uploads except patches, but that's not the case for the
purpose. If there are text files only, please gist them somewhere and post a link. Otherwise,
probably no way around than sharing them through dropbox or a similar service.
Thanks.
------------------------------------------------------------------------
[2017-02-01 06:50:10] ckmailid at gmail dot com
Hi, i generate a sample key and made a sample pfx file that can reproduce but i didn't find any
option to attach a file. I am afraid but can you please guide me where to upload sample pfx file.
------------------------------------------------------------------------
[2017-01-31 13:48:47] ab@php.net
Thanks for the report. Could you provide the backtrace? Also, were it possible to get some .pfx file
for debugging? If not your exact file, then any that reproduces.
Thanks.
------------------------------------------------------------------------
[2017-01-31 13:13:19] ckmailid at gmail dot com
Description:
------------
PHP process crashes when i use a pfx file to read using function openssl_pkcs12_read with valid
password.
But it gives error if password is wrong, that is working fine.
That pfx file is working well with openssl command line utility
Environment :
PHP : 7 .0.9
OS: windows 10
Server: IIS, Using Fast CGI
certificate : It is specially exported certificate from windows. when a highly secure certificate is
exported , it asks for login user password, and after 4 attempt with wrong password it export the
certificate even after wrong password.
You can do it by import a pfx file that with enabling strong private key encrypting checkbox on
wizard and after finish set security level HIGH.
I tried it on linux with gdb, it shows Segmentation fault (core dumped).
Test script:
---------------
if (!$cert_store = file_get_contents("sample_export.pfx")) {
echo "Error: Unable to read the cert file\n";
exit;
}
if (openssl_pkcs12_read($cert_store, $cert_info, "csos")) {
echo "Certificate Information\n";
print_r($cert_info);
} else {
echo "Error: Unable to read the cert store.\n";
exit;
}
Expected result:
----------------
it will crash the PHP process.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74022&edit=1