[php-src] Issue #9026: do not silently truncate the key in openssl_encrypt()

From: Date: Sat, 16 Jul 2022 09:17:26 +0000
Subject: [php-src] Issue #9026: do not silently truncate the key in openssl_encrypt()
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-241937@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/9026
Author: divinity76

### Description

Silently truncating keys in security-sensitive code/API's sounds horrible. 
However, given PHP's commitment to backwards-compatibility, perhaps make truncation
"deprecated" for a while, and make it throw in the future?

The following code:

```php
<?php
$cipher = "aes-128-ctr";
$data = "test";
$passphrase = "KeyLengthIs16_12";
$iv = str_repeat("\x00", openssl_cipher_iv_length($cipher));
$flags = 0;

$m1 = openssl_encrypt(
    $data,
    $cipher,
    $passphrase,
    $flags,
    $iv
);

$passphrase .= "3";
$m2 = openssl_encrypt(
    $data,
    $cipher,
    $passphrase,
    $flags,
    $iv
);
var_dump($m1 === $m2);
```

Resulted in this output:
```
bool(true);
```

But I expected this output instead:
```
Fatal error: Uncaught LengthException: cipher key is too long, this cipher expects a key of
precisely 16 bytes, 17 bytes provided.
```


### PHP Version

PHP 8.1.7

### Operating System

Ubuntu 22.04


Thread (1 message)

  • divinity76
« previous php.bugs (#241937) next »