#25117 [Opn->Csd]: MD5 checksum should be checked case-insensitive
| From: | cellog@php.net | Date: | Sun, 17 Aug 2003 18:01:56 +0000 |
| Subject: | #25117 [Opn->Csd]: MD5 checksum should be checked case-insensitive | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-19942@lists.php.net to get a copy of this message | ||
ID: 25117
Updated by: cellog@php.net
Reported By: christian at wenz dot org
-Status: Open
+Status: Closed
Bug Type: PEAR related
Operating System: any
PHP Version: 4.3.3RC3
Assigned To: cellog
New Comment:
This bug has been fixed in CVS.
In case this was a PHP problem, snapshots of the sources are packaged
every three hours; this change will be in the next snapshot. You can
grab the snapshot at http://snaps.php.net/.
In case this was a documentation problem, the fix will show up soon at
http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites in short time.
Thank you for the report, and for helping us make PHP better.
thanks for the catch
Previous Comments:
------------------------------------------------------------------------
[2003-08-17 09:48:21] christian at wenz dot org
Description:
------------
the MD5 checksum in package.xml for a file only works with the PEAR
installer when provided in lowercase. If capital letters (A-F) are
used, a "bad checksum" warning is returned.
Reason: md5_file() seems to return MD5 checksums in lowercase, however
some MD5 calculation tools (e.g. the command line tool at
http://www.fourmilab.ch/md5/) return checksums in upper
case.
The "error" (if you can call it that way) is in line 276 of
PEAR\Installer.php:
if ($md5sum == $atts['md5sum']) {
The following would eliminate the problem:
if ($md5sum == strtolower($atts['md5sum'])) {
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=25117&edit=1