Bug #80232 [NEW]: openssl_decrypt() error with aes-128-ocb fail to set openssl_error_string()

From: Date: Wed, 14 Oct 2020 01:27:18 +0000
Subject: Bug #80232 [NEW]: openssl_decrypt() error with aes-128-ocb fail to set openssl_error_string()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229602@lists.php.net to get a copy of this message
From:             divinity76 at gmail dot com
Operating system: 
PHP version:      7.2.34
Package:          OpenSSL related
Bug Type:         Bug
Bug description:openssl_decrypt() error with aes-128-ocb fail to set openssl_error_string()

Description:
------------
it seems some openssl_decrypt() decryption error with aes-128-ocb fail
to register on openssl_error_string()

Test script:
---------------
<?php
declare(strict_types=1);
ini_set('display_errors','On');
error_reporting(E_ALL);
header("Content-Type: text/plain;charset=utf-8");
ini_set('html_errors','0');
$algo = 'aes-128-ocb';
$data_to_encrypt = $key = $iv = str_repeat("\x00",
openssl_cipher_iv_length($algo));
$opts = OPENSSL_RAW_DATA | OPENSSL_ZERO_PADDING;
$encrypted = openssl_encrypt($data_to_encrypt, $algo, $key, $opts ,
$iv);
if(false===$encrypted || openssl_error_string() !== false){
    die("encryption error ".openssl_error_string());
}
$decrypted = openssl_decrypt($encrypted, $algo, $key, $opts, $iv);
if(($encrypted !== $data_to_encrypt) && ($data_to_encrypt ===
$decrypted)){
    echo "ok";
}else{
    echo "error: ";
    var_dump([
        "original"=>$data_to_encrypt,
        "encrypted"=>$encrypted,
        "decrypted"=>$decrypted,
        "openssl_error_string" => openssl_error_string()
    ]);
}


Expected result:
----------------
i either expected "ok", or expected openssl_error_string() to contain
something other than bool(false) 

Actual result:
--------------
error: array(4) {
  ["original"]=>
  string(12) "������������"
  ["encrypted"]=>
  string(12) "{��f�g]�WG�"
  ["decrypted"]=>
  bool(false)
  ["openssl_error_string"]=>
  bool(false)
}

-- 
Edit bug report at https://bugs.php.net/bug.php?id=80232&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=80232&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=80232&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=80232&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=80232&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=80232&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=80232&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=80232&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=80232&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=80232&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=80232&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80232&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=80232&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=80232&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=80232&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=80232&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=80232&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=80232&r=mysqlcfg


Thread (4 messages)

« previous php.bugs (#229602) next »