Bug #74099 [Opn->Csd]: Memory leak with openssl_encrypt()
Edit report at https://bugs.php.net/bug.php?id=74099&edit=1
ID: 74099
Updated by: nikic@php.net
Reported by: marcel at webdisplay dot nl
Summary: Memory leak with openssl_encrypt()
-Status: Open
+Status: Closed
Type: Bug
Package: OpenSSL related
Operating System: macOS Sierra
PHP Version: 7.1.1
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of andrew.nester.dev@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=15b8b124ae1017dc31dae46cee73b702d77f85b8
Log: Fixed #74099 - Memory leak with openssl_encrypt()
Previous Comments:
------------------------------------------------------------------------
[2017-02-17 09:36:43] andrew dot nester dot dev at gmail dot com
Thanks for reporting this issue! Just added PR with fix for this.
------------------------------------------------------------------------
[2017-02-15 09:30:12] marcel at webdisplay dot nl
Description:
------------
Encrypting an empty string in AES-256-GCM should return an empty string and valid tag but instead it
returns 32 bytes of data from memory which could leak information.
Test script:
---------------
$aad = random_bytes(32);
$iv = random_bytes(16);
$key = random_bytes(32);
$plaintext = '';
$tag = null;
$ciphertext = openssl_encrypt($plaintext, 'aes-256-gcm', $key, \OPENSSL_RAW_DATA, $iv,
$tag, $aad);
// $ciphertext should be an empty string but it is not in PHP 7.1.*
// Instead it returns random data from memory!
printf("ciphertext=%s, tag=%s", bin2hex($ciphertext), bin2hex($tag));
Expected result:
----------------
An empty string must be returned
Actual result:
--------------
A 32-byte string from memory is returned
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74099&edit=1
Thread (3 messages)