Sec Bug->Bug #72776 [Csd]: Invalid parameter in memcpy function trough openssl_pbkdf2
| From: | stas@php.net | Date: | Mon, 13 Feb 2017 01:45:52 +0000 |
| Subject: | Sec Bug->Bug #72776 [Csd]: Invalid parameter in memcpy function trough openssl_pbkdf2 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207356@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=72776&edit=1
ID: 72776
Updated by: stas@php.net
Reported by: marceloje at gmail dot com
Summary: Invalid parameter in memcpy function trough
openssl_pbkdf2
Status: Closed
-Type: Security
+Type: Bug
Package: OpenSSL related
Operating System: Linux
PHP Version: 5.6.24
Assigned To: bukka
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2016-11-06 20:50:23] bukka@php.net
Fixed by http://git.php.net/?p=php-src.git;a=commit;h=493b2bff02531b0ead233177a2a0846c75e94777
------------------------------------------------------------------------
[2016-11-06 20:49:18] bukka@php.net
Fixed in 5.6
------------------------------------------------------------------------
[2016-11-03 03:40:55] stas@php.net
5.5 is EOL. Please feel free to commit to 5.6 and above.
------------------------------------------------------------------------
[2016-11-02 19:49:04] bukka@php.net
From the quick check, it would require very high memory limit and the app would have allow user to
set key length which has very small probability IMHO. I would consider it as low severity.
If they are no objections, I will commit a fix to the public repo to 5.6 only and leave it on RM to
decide if it should be ported to 5.5.
------------------------------------------------------------------------
[2016-08-07 21:26:21] stas@php.net
Doesn't look to me like security issue. Assigning to OpenSSL maintainer.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=72776
--
Edit this bug report at https://bugs.php.net/bug.php?id=72776&edit=1