Sec Bug->Bug #76842 [Ver]: password_verify returns true comparing null and \0

From: Date: Sun, 02 Dec 2018 05:01:57 +0000
Subject: Sec Bug->Bug #76842 [Ver]: password_verify returns true comparing null and \0
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218243@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76842&edit=1 ID: 76842 Updated by: stas@php.net Reported by: leon at valkenb dot org -Summary: Possible authentication attack vector +Summary: password_verify returns true comparing null and \0 Status: Verified -Type: Security +Type: Bug Package: *Encryption and hash functions Operating System: Ubuntu PHP Version: 7.1.21 Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2018-12-02 05:01:19] stas@php.net Doesn't seem to be likely scenario to have null as valid password. ------------------------------------------------------------------------ [2018-09-06 11:37:59] cmb@php.net The following patch has been added/updated: Patch Name: password-as-path Revision: 1536233879 URL: https://bugs.php.net/patch-display.php?bug=76842&patch=password-as-path&revision=1536233879 ------------------------------------------------------------------------ [2018-09-06 11:37:54] cmb@php.net > Is there any way i can see ug #74473 as its marked private? No, sorry. Security reports are private to the reporter, and to those with sec karma. Anyhow, on a closer look I'm not sure this is really a bug at all. password_hash()ing NULL is equivalent to password_hash()ing an empty string, and this should be checked and prohibited in the first place in userland (“password too short”). I consider it unlikely that a user would circumvent this check by passing a string of NULs. Nonetheless, the password API should probably check for NUL bytes in given passwords to prohibit such misuse. ------------------------------------------------------------------------ [2018-09-05 20:34:32] leon at valkenb dot org Is there any way i can see ug #74473 as its marked private? ------------------------------------------------------------------------ [2018-09-05 10:35:18] cmb@php.net This might be related to bug #74473. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=76842 -- Edit this bug report at https://bugs.php.net/bug.php?id=76842&edit=1

« previous php.bugs (#218243) next »