[php-src] Issue #8397: crypt() accepts invalid characters in salt

From: Date: Tue, 19 Apr 2022 10:58:17 +0000
Subject: [php-src] Issue #8397: crypt() accepts invalid characters in salt
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-241070@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/8397 Comment Author: cmb69 Well, PHP's implementation follows the [informal specification](https://akkadia.org/drepper/SHA-crypt.txt); actually, the PHP implementation is closely based on the given implementation (it might be identical). And that specification does not apply base64-like encoding to the salt when producing the result string. I think not base64-like encoding the salt is somewhat strange, but I don't think we can change that for BC reasons. Not sure what to do; maybe documenting the behavior explicitly is the best solution for now. That might require users to pass in a properly encoded salt, what obviously would reduce the entropy, but that may not be a problem in practice.

« previous php.bugs (#241070) next »