Bug #74099 [Com]: Memory leak with openssl_encrypt()

From: Date: Fri, 17 Feb 2017 09:36:45 +0000
Subject: Bug #74099 [Com]: Memory leak with openssl_encrypt()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-207424@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74099&edit=1 ID: 74099 Comment by: andrew dot nester dot dev at gmail dot com Reported by: marcel at webdisplay dot nl Summary: Memory leak with openssl_encrypt() Status: Open Type: Bug Package: OpenSSL related Operating System: macOS Sierra PHP Version: 7.1.1 Block user comment: N Private report: N New Comment: Thanks for reporting this issue! Just added PR with fix for this. Previous Comments: ------------------------------------------------------------------------ [2017-02-15 09:30:12] marcel at webdisplay dot nl Description: ------------ Encrypting an empty string in AES-256-GCM should return an empty string and valid tag but instead it returns 32 bytes of data from memory which could leak information. Test script: --------------- $aad = random_bytes(32); $iv = random_bytes(16); $key = random_bytes(32); $plaintext = ''; $tag = null; $ciphertext = openssl_encrypt($plaintext, 'aes-256-gcm', $key, \OPENSSL_RAW_DATA, $iv, $tag, $aad); // $ciphertext should be an empty string but it is not in PHP 7.1.* // Instead it returns random data from memory! printf("ciphertext=%s, tag=%s", bin2hex($ciphertext), bin2hex($tag)); Expected result: ---------------- An empty string must be returned Actual result: -------------- A 32-byte string from memory is returned ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74099&edit=1

« previous php.bugs (#207424) next »