Doc #68328 [Asn->Csd]: hash_equals does not mention that a difference in str length will leak

From: Date: Thu, 30 Oct 2014 10:07:39 +0000
Subject: Doc #68328 [Asn->Csd]: hash_equals does not mention that a difference in str length will leak
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11599@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68328&edit=1 ID: 68328 Updated by: mikemike@php.net Reported by: asphp at dsgml dot com Summary: hash_equals does not mention that a difference in str length will leak -Status: Assigned +Status: Closed Type: Documentation Problem Package: Documentation problem PHP Version: Irrelevant Assigned To: mikemike Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2014-10-30 10:07:18] mikemike@php.net A patch has been added reflecting this change. It may take a few hours to make its way across all mirrors. Thank you ------------------------------------------------------------------------ [2014-10-30 10:04:52] mikemike@php.net Automatic comment from SVN on behalf of mikemike Revision: http://svn.php.net/viewvc/?view=revision&revision=335150 Log: Added word 'immediately' to add clarity, address bug #68328 ------------------------------------------------------------------------ [2014-10-30 09:40:09] asphp at dsgml dot com Also on the note change it to say "FALSE is returned immediately and the". (i.e. add the word immediately.) ------------------------------------------------------------------------ [2014-10-30 09:38:45] asphp at dsgml dot com I did not see the note. The information in it should be added to the Description near "This function should be used to mitigate timing attacks". ------------------------------------------------------------------------ [2014-10-30 09:26:34] mikemike@php.net There is already a note present, which reads: -- Note: Both arguments must be of the same length to be compared successfully. When arguments of differing length are supplied, FALSE is returned and the length of the known string may be leaked in case of a timing attack. -- Can you supply an instance where returning false is an issue? ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68328 -- Edit this bug report at https://bugs.php.net/bug.php?id=68328&edit=1

« previous php.doc.bugs (#11599) next »