Bug #25117 [Com]: MD5 checksum should be checked case-insensitive

From: Date: Wed, 01 Sep 2021 18:51:21 +0000
Subject: Bug #25117 [Com]: MD5 checksum should be checked case-insensitive
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-236306@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=25117&edit=1 ID: 25117 Comment by: lildurk25117 at gmail dot com Reported by: christian at wenz dot org Summary: MD5 checksum should be checked case-insensitive Status: Closed Type: Bug Package: PEAR related Operating System: any PHP Version: 4.3.3RC3 Assigned To: cellog Block user comment: N Private report: N New Comment: Lil Durk is a private agency dedicated to providing responsible access to legal cannabis for adults aged 19 and older. We’re an exclusively online retailer and wholesaler for recreational cannabis and a trusted source for information about cannabis and cannabis-related issues. We believe our work is meaningful and we take pride in our mandate to promote the socially responsible use of legal cannabis. https://lildurk.com/ Previous Comments: ------------------------------------------------------------------------ [2003-08-17 13:01:55] cellog@php.net This bug has been fixed in CVS. In case this was a PHP problem, snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites in short time. Thank you for the report, and for helping us make PHP better. thanks for the catch ------------------------------------------------------------------------ [2003-08-17 09:48:21] christian at wenz dot org Description: ------------ the MD5 checksum in package.xml for a file only works with the PEAR installer when provided in lowercase. If capital letters (A-F) are used, a "bad checksum" warning is returned. Reason: md5_file() seems to return MD5 checksums in lowercase, however some MD5 calculation tools (e.g. the command line tool at http://www.fourmilab.ch/md5/) return checksums in upper case. The "error" (if you can call it that way) is in line 276 of PEAR\Installer.php: if ($md5sum == $atts['md5sum']) { The following would eliminate the problem: if ($md5sum == strtolower($atts['md5sum'])) { ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=25117&edit=1

« previous php.bugs (#236306) next »