Bug #13052 Updated: Empty $key in mcrypt_generic_init causes segmentation fault

From: Date: Fri, 07 Sep 2001 06:25:47 +0000
Subject: Bug #13052 Updated: Empty $key in mcrypt_generic_init causes segmentation fault
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-65311@lists.php.net to get a copy of this message
ID: 13052 Updated by: derick Reported By: naomi@humanfactors.edu.au Old Status: Assigned Status: Closed Bug Type: mcrypt related Operating System: GNU 1.0.3 PHP Version: 4.0.6 Assigned To: derick New Comment: Fixed in CVS (will be in 4.0.7) Previous Comments: ------------------------------------------------------------------------ [2001-08-30 04:08:38] naomi@humanfactors.edu.au Calling mcrypt_generic_init with an empty $key causes a segmentation fault in Apache. Obviously $key should not be empty, but errors will be made, so perhaps a parse error could be generated in this event rather than a crash. Example Code <?php //Open encryption module $td = mcrypt_module_open (MCRYPT_ARCFOUR, "", MCRYPT_MODE_STREAM, ""); srand ((double) microtime() * 1000000); $iv = mcrypt_create_iv (mcrypt_enc_get_iv_size ($td), MCRYPT_RAND); //Encrypt data $data = "message"; mcrypt_generic_init($td, $key, $iv);//HERE IS THE PROBLEM $encrypted_data = mcrypt_generic ($td, $data); mcrypt_generic_end ($td); ?> ------------------------------------------------------------------------ Edit this bug report at http://bugs.php.net/?id=13052&edit=1

« previous php.dev (#65311) next »