Sec Bug->Bug #76842 [Ver]: password_verify returns true comparing null and \0
| From: | stas@php.net | Date: | Sun, 02 Dec 2018 05:01:57 +0000 |
| Subject: | Sec Bug->Bug #76842 [Ver]: password_verify returns true comparing null and \0 | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218243@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76842&edit=1
ID: 76842
Updated by: stas@php.net
Reported by: leon at valkenb dot org
-Summary: Possible authentication attack vector
+Summary: password_verify returns true comparing null and \0
Status: Verified
-Type: Security
+Type: Bug
Package: *Encryption and hash functions
Operating System: Ubuntu
PHP Version: 7.1.21
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2018-12-02 05:01:19] stas@php.net
Doesn't seem to be likely scenario to have null as valid password.
------------------------------------------------------------------------
[2018-09-06 11:37:59] cmb@php.net
The following patch has been added/updated:
Patch Name: password-as-path
Revision: 1536233879
URL: https://bugs.php.net/patch-display.php?bug=76842&patch=password-as-path&revision=1536233879
------------------------------------------------------------------------
[2018-09-06 11:37:54] cmb@php.net
> Is there any way i can see ug #74473 as its marked private?
No, sorry. Security reports are private to the reporter, and to
those with sec karma.
Anyhow, on a closer look I'm not sure this is really a bug at all.
password_hash()ing NULL is equivalent to password_hash()ing an
empty string, and this should be checked and prohibited in the
first place in userland (âpassword too shortâ). I consider it
unlikely that a user would circumvent this check by passing a
string of NULs.
Nonetheless, the password API should probably check for NUL bytes
in given passwords to prohibit such misuse.
------------------------------------------------------------------------
[2018-09-05 20:34:32] leon at valkenb dot org
Is there any way i can see ug #74473 as its marked private?
------------------------------------------------------------------------
[2018-09-05 10:35:18] cmb@php.net
This might be related to bug #74473.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76842
--
Edit this bug report at https://bugs.php.net/bug.php?id=76842&edit=1