#21039 [Opn->Bgs]: crash when IV is not set
| From: | iliaa@php.net | Date: | Mon, 16 Dec 2002 08:44:41 +0000 |
| Subject: | #21039 [Opn->Bgs]: crash when IV is not set | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-27827@lists.php.net to get a copy of this message | ||
ID: 21039
Updated by: iliaa@php.net
Reported By: mbretter@php.net
-Status: Open
+Status: Bogus
Bug Type: mcrypt related
Operating System: FreeBSD 4.7
PHP Version: 4.3.0RC3
New Comment:
Sorry, but your problem does not imply a bug in PHP itself. For a
list of more appropriate places to ask for help using PHP, please
visit http://www.php.net/support.php as this bug system
is not the
appropriate forum for asking support questions.
Thank you for your interest in PHP.
libmcrypt author has already been contacted with the fix to the
problem.
Previous Comments:
------------------------------------------------------------------------
[2002-12-16 02:27:09] mbretter@php.net
I'm running FreeBSD 4.7 with libmcrypt 2.5.3.
There seems to be a bug in libmcrypt, the crash occurs if you call
mcrypt_generic(), but without valid IV. Here's a short script:
$td = mcrypt_module_open ('des', '', 'cbc', '');
$iv = mcrypt_create_iv (mcrypt_enc_get_iv_size ($td), MCRYPT_RAND);
mcrypt_generic_init ($td, substr($nthash, 0, 7));
$res = mcrypt_generic ($td, $challenge);
changing:
mcrypt_generic_init ($td, substr($nthash, 0, 7));
to:
mcrypt_generic_init ($td, substr($nthash, 0, 7), $iv);
solves the problem :-)
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=21039&edit=1