Bug #74700 [NEW]: Faulty returned values openssl_pkey_get_details

From: Date: Tue, 06 Jun 2017 09:53:35 +0000
Subject: Bug #74700 [NEW]: Faulty returned values openssl_pkey_get_details
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209389@lists.php.net to get a copy of this message
From: nothingam at protonmail dot com Operating system: Debian PHP version: 5.6.30 Package: OpenSSL related Bug Type: Bug Bug description:Faulty returned values openssl_pkey_get_details Description: ------------ The 'openssl_pkey_get_details' function for OPENSSL_KEYTYPE_DH typed keys seems to return faulty 'pub_key's (probably 'priv_key's too). If the last byte is zero byte (0x00), the returned value in the $ret['dh']['pub_key'] is shorter than expected (obviously with one byte in this case). I've successfully reproduced the problem on: - Windows: PHP 5.5.12 (cli) (built: Apr 30 2014 11:20:58) - Debian: PHP 5.6.30-0+deb8u1 (cli) (built: Feb 8 2017 08:50:21) --- From manual page: http://www.php.net/function.openssl-pkey-get-details --- Test script: --------------- $DH_DEFAULT_PRIME = "FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD129024E088A67CC74020BBEA63B139B22514A08798E3404DDEF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7EDEE386BFB5A899FA5AE9F24117C4B1FE649286651ECE65381FFFFFFFFFFFFFFFF"; $DH_DEFAULT_GENERATOR = '02'; for($i=0; $i < 500; $i++) { $details = array(); $details['p'] = pack('H*', $DH_DEFAULT_PRIME); $details['g'] = pack('H*', $DH_DEFAULT_GENERATOR); $res = openssl_pkey_new(array("dh" => $details)); $details = openssl_pkey_get_details($res); $privateKey = $details['dh']['priv_key']; $publicKey = $details['dh']['pub_key']; if (strlen($publicKey) != $details['bits']/8) { echo "Whooaa!"; } } -- Edit bug report at https://bugs.php.net/bug.php?id=74700&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74700&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74700&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74700&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=74700&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=74700&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=74700&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=74700&r=needscript Try newer version: https://bugs.php.net/fix.php?id=74700&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=74700&r=support Expected behavior: https://bugs.php.net/fix.php?id=74700&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=74700&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=74700&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=74700&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74700&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=74700&r=dst IIS Stability: https://bugs.php.net/fix.php?id=74700&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=74700&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=74700&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=74700&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=74700&r=mysqlcfg

« previous php.bugs (#209389) next »