Bug #75407 [NEW]: No warning thrown for a nonexistant cipher method

From: Date: Thu, 19 Oct 2017 11:48:29 +0000
Subject: Bug #75407 [NEW]: No warning thrown for a nonexistant cipher method
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-211777@lists.php.net to get a copy of this message
From:             faxitnow at yahoo dot ca
Operating system: 
PHP version:      Irrelevant
Package:          OpenSSL related
Bug Type:         Bug
Bug description:No warning thrown for a nonexistant cipher method

Description:
------------
Using $encrypted = openssl_encrypt($dataEncrypt, "AES-256-XTS", $key, 0,
$iv);

Does not throw a warning for a nonexistant cipher method. However, when
replacing the "S" with a "C" for example such as "AES-256-XTC" or any
letter from the alphabet other than "S" (A to Z except S) does throw a
warning such as:

Warning: openssl_encrypt(): Unknown cipher algorithm in path/to/file.php
on line X


Test script:
---------------
$key = hash_hmac("sha512", "You can decrypt this all day long, won't get
you closer to the truth", "myKey");
$iv = openssl_random_pseudo_bytes(16);
$adminVal = filter_var($userData['is_admin'], FILTER_VALIDATE_BOOLEAN);
$userName = $userData["name"];
$dataEncrypt = $adminVal.$userName;
$encrypted = openssl_encrypt($dataEncrypt, "AES-256-XTS", $key, 0,
$iv);

As per a question posted on Stack Overflow at the following URL: 
https://stackoverflow.com/q/46821439/


Expected result:
----------------
The expected result should have thrown a warning such as:
Warning: openssl_encrypt(): Unknown cipher algorithm in path/to/file.php
on line X

Actual result:
--------------
No warning thrown, just an empty result. 
string(0) "" when using var_dump($encrypted); from the test script
included.

-- 
Edit bug report at https://bugs.php.net/bug.php?id=75407&edit=1
-- 
Try a snapshot (PHP 5.4):   https://bugs.php.net/fix.php?id=75407&r=trysnapshot54
Try a snapshot (PHP 5.5):   https://bugs.php.net/fix.php?id=75407&r=trysnapshot55
Try a snapshot (trunk):     https://bugs.php.net/fix.php?id=75407&r=trysnapshottrunk
Fixed in SVN:               https://bugs.php.net/fix.php?id=75407&r=fixed
Fixed in release:           https://bugs.php.net/fix.php?id=75407&r=alreadyfixed
Need backtrace:             https://bugs.php.net/fix.php?id=75407&r=needtrace
Need Reproduce Script:      https://bugs.php.net/fix.php?id=75407&r=needscript
Try newer version:          https://bugs.php.net/fix.php?id=75407&r=oldversion
Not developer issue:        https://bugs.php.net/fix.php?id=75407&r=support
Expected behavior:          https://bugs.php.net/fix.php?id=75407&r=notwrong
Not enough info:            https://bugs.php.net/fix.php?id=75407&r=notenoughinfo
Submitted twice:            https://bugs.php.net/fix.php?id=75407&r=submittedtwice
register_globals:           https://bugs.php.net/fix.php?id=75407&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=75407&r=php4
Daylight Savings:           https://bugs.php.net/fix.php?id=75407&r=dst
IIS Stability:              https://bugs.php.net/fix.php?id=75407&r=isapi
Install GNU Sed:            https://bugs.php.net/fix.php?id=75407&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=75407&r=float
No Zend Extensions:         https://bugs.php.net/fix.php?id=75407&r=nozend
MySQL Configuration Error:  https://bugs.php.net/fix.php?id=75407&r=mysqlcfg



Thread (8 messages)

« previous php.bugs (#211777) next »