Doc #68328 [Asn->Csd]: hash_equals does not mention that a difference in str length will leak
| From: | mikemike@php.net | Date: | Thu, 30 Oct 2014 10:07:39 +0000 |
| Subject: | Doc #68328 [Asn->Csd]: hash_equals does not mention that a difference in str length will leak | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-11599@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68328&edit=1
ID: 68328
Updated by: mikemike@php.net
Reported by: asphp at dsgml dot com
Summary: hash_equals does not mention that a difference in
str length will leak
-Status: Assigned
+Status: Closed
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Assigned To: mikemike
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2014-10-30 10:07:18] mikemike@php.net
A patch has been added reflecting this change. It may take a few hours to make its way across all
mirrors.
Thank you
------------------------------------------------------------------------
[2014-10-30 10:04:52] mikemike@php.net
Automatic comment from SVN on behalf of mikemike
Revision: http://svn.php.net/viewvc/?view=revision&revision=335150
Log: Added word 'immediately' to add clarity, address bug #68328
------------------------------------------------------------------------
[2014-10-30 09:40:09] asphp at dsgml dot com
Also on the note change it to say "FALSE is returned immediately and the". (i.e. add the
word immediately.)
------------------------------------------------------------------------
[2014-10-30 09:38:45] asphp at dsgml dot com
I did not see the note.
The information in it should be added to the Description near "This function should be used to
mitigate timing attacks".
------------------------------------------------------------------------
[2014-10-30 09:26:34] mikemike@php.net
There is already a note present, which reads:
--
Note:
Both arguments must be of the same length to be compared successfully. When arguments of differing
length are supplied, FALSE is returned and the length of the known string may be leaked in case of a
timing attack.
--
Can you supply an instance where returning false is an issue?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68328
--
Edit this bug report at https://bugs.php.net/bug.php?id=68328&edit=1