Bug #74022 [Com]: PHP Fast CGI crashes when reading from a pfx file with valid password.

From: Date: Wed, 17 May 2017 09:56:06 +0000
Subject: Bug #74022 [Com]: PHP Fast CGI crashes when reading from a pfx file with valid password.
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209163@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74022&edit=1 ID: 74022 Comment by: falundir at gmail dot com Reported by: ckmailid at gmail dot com Summary: PHP Fast CGI crashes when reading from a pfx file with valid password. Status: Closed Type: Bug Package: OpenSSL related Operating System: Windows 10 PHP Version: 7.0.15 Block user comment: N Private report: N New Comment: I've confirmed this suspicion. Following patch (against 7.1.5) fixes the problem: @@ -2972,11 +2972,9 @@ PHP_FUNCTION(openssl_pkcs12_read) } if (ca && sk_X509_num(ca)) { - int num; array_init(&zextracerts); - num = sk_X509_num(ca); - for (i = 0; i < num; i++) { + for (i = 0; i < sk_X509_num(ca); i++) { zval zextracert; X509* aCA = sk_X509_pop(ca); if (!aCA) break; Previous Comments: ------------------------------------------------------------------------ [2017-05-17 07:45:39] falundir at gmail dot com Looking at the diff, I think that sk_X509_num(ca) should be evaluated before the for-loop, because sk_X509_pop probably changes the sk_X509_num result. ------------------------------------------------------------------------ [2017-05-17 06:55:54] falundir at gmail dot com Probably this is the fix that broke openssl_pkcs12_read - starting from PHP 7.0.17 and 7.1.3 this function returns only one certificate in 'extracerts', even when there are more than one. See here: https://3v4l.org/r3brq ------------------------------------------------------------------------ [2017-02-02 12:09:28] ab@php.net Automatic comment on behalf of ab Revision: http://git.php.net/?p=php-src.git;a=commit;h=6fc0ae638acd2a66a4181078f4ac5d789762d9de Log: Fixed #74022 PHP Fast CGI crashes when reading from a pfx file. ------------------------------------------------------------------------ [2017-02-01 13:01:57] ckmailid at gmail dot com Thanks for the suggestion, please use the following link to get the file https://drive.google.com/file/d/0Bzazdkn-4vEOTk5VYW8wUTM1LXM/view?usp=sharing let me know in case of any difficulties. ------------------------------------------------------------------------ [2017-02-01 12:55:10] ab@php.net This tracker doesn't allow file uploads except patches, but that's not the case for the purpose. If there are text files only, please gist them somewhere and post a link. Otherwise, probably no way around than sharing them through dropbox or a similar service. Thanks. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74022 -- Edit this bug report at https://bugs.php.net/bug.php?id=74022&edit=1

« previous php.bugs (#209163) next »