Bug #13052 Updated: Empty $key in mcrypt_generic_init causes segmentation fault
| From: | derick@php.net | Date: | Fri, 07 Sep 2001 06:25:47 +0000 |
| Subject: | Bug #13052 Updated: Empty $key in mcrypt_generic_init causes segmentation fault | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-65311@lists.php.net to get a copy of this message | ||
ID: 13052
Updated by: derick
Reported By: naomi@humanfactors.edu.au
Old Status: Assigned
Status: Closed
Bug Type: mcrypt related
Operating System: GNU 1.0.3
PHP Version: 4.0.6
Assigned To: derick
New Comment:
Fixed in CVS (will be in 4.0.7)
Previous Comments:
------------------------------------------------------------------------
[2001-08-30 04:08:38] naomi@humanfactors.edu.au
Calling mcrypt_generic_init with an empty $key causes a segmentation fault in Apache. Obviously $key
should not be empty, but errors will be made, so perhaps a parse error could be generated in this
event rather than a crash.
Example Code
<?php
//Open encryption module
$td = mcrypt_module_open (MCRYPT_ARCFOUR, "", MCRYPT_MODE_STREAM, "");
srand ((double) microtime() * 1000000);
$iv = mcrypt_create_iv (mcrypt_enc_get_iv_size ($td), MCRYPT_RAND);
//Encrypt data
$data = "message";
mcrypt_generic_init($td, $key, $iv);//HERE IS THE PROBLEM
$encrypted_data = mcrypt_generic ($td, $data);
mcrypt_generic_end ($td);
?>
------------------------------------------------------------------------
Edit this bug report at http://bugs.php.net/?id=13052&edit=1