Bug #74700 [NEW]: Faulty returned values openssl_pkey_get_details
| From: | nothingam at protonmail dot com | Date: | Tue, 06 Jun 2017 09:53:35 +0000 |
| Subject: | Bug #74700 [NEW]: Faulty returned values openssl_pkey_get_details | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-209389@lists.php.net to get a copy of this message | ||
From: nothingam at protonmail dot com
Operating system: Debian
PHP version: 5.6.30
Package: OpenSSL related
Bug Type: Bug
Bug description:Faulty returned values openssl_pkey_get_details
Description:
------------
The 'openssl_pkey_get_details' function for OPENSSL_KEYTYPE_DH typed
keys seems to return faulty 'pub_key's (probably 'priv_key's too).
If the last byte is zero byte (0x00), the returned value in the
$ret['dh']['pub_key'] is shorter than expected (obviously with one byte
in this case).
I've successfully reproduced the problem on:
- Windows: PHP 5.5.12 (cli) (built: Apr 30 2014 11:20:58)
- Debian: PHP 5.6.30-0+deb8u1 (cli) (built: Feb 8 2017 08:50:21)
---
From manual page: http://www.php.net/function.openssl-pkey-get-details
---
Test script:
---------------
$DH_DEFAULT_PRIME =
"FFFFFFFFFFFFFFFFC90FDAA22168C234C4C6628B80DC1CD129024E088A67CC74020BBEA63B139B22514A08798E3404DDEF9519B3CD3A431B302B0A6DF25F14374FE1356D6D51C245E485B576625E7EC6F44C42E9A637ED6B0BFF5CB6F406B7EDEE386BFB5A899FA5AE9F24117C4B1FE649286651ECE65381FFFFFFFFFFFFFFFF";
$DH_DEFAULT_GENERATOR = '02';
for($i=0; $i < 500; $i++) {
$details = array();
$details['p'] = pack('H*', $DH_DEFAULT_PRIME);
$details['g'] = pack('H*', $DH_DEFAULT_GENERATOR);
$res = openssl_pkey_new(array("dh" => $details));
$details = openssl_pkey_get_details($res);
$privateKey = $details['dh']['priv_key'];
$publicKey = $details['dh']['pub_key'];
if (strlen($publicKey) != $details['bits']/8) {
echo "Whooaa!";
}
}
--
Edit bug report at https://bugs.php.net/bug.php?id=74700&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74700&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74700&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74700&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=74700&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=74700&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=74700&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=74700&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=74700&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=74700&r=support
Expected behavior: https://bugs.php.net/fix.php?id=74700&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=74700&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=74700&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=74700&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74700&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=74700&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=74700&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=74700&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=74700&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=74700&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=74700&r=mysqlcfg