#76 [Opn->Csd]: A password of "test<space>" is not validated
| From: | yavo@php.net | Date: | Mon, 13 Oct 2003 08:10:54 +0000 |
| Subject: | #76 [Opn->Csd]: A password of "test<space>" is not validated | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-22631@lists.php.net to get a copy of this message | ||
ID: 76
Updated by: yavo@php.net
Reported By: php at untz dot cx
-Status: Open
+Status: Closed
Bug Type: Auth
Operating System: win2k
PHP Version: 4.3.2
New Comment:
This bug has been fixed in CVS.
In case this was a documentation problem, the fix will show up at the
end of next Sunday (CET) on pear.php.net.
In case this was a pear.php.net website problem, the change will show
up on the website in short time.
Thank you for the report, and for helping us make PEAR better.
Fixed bugs in DB and MDB container
changed trim($password) to trim($password, "\r\n")
to trim only new line and carriage return chars, am not sure if trim is
really needed there thou.
Yavo
Previous Comments:
------------------------------------------------------------------------
[2003-10-07 09:40:57] php at untz dot cx
Description:
------------
Due to $password being trim()'d before being validated, a password that
begins or ends in a space (or any whitespace) is not validated
correctly.
The second trim is alright if using MD5() crypting, but will cause
problems if using no crypting. ie $password1 == $password2
Reproduce code:
---------------
http://cvs.php.net/annotate.php/pear/Auth/Container/DB.php?rev=1.38
Line 256 of DB.php and similar in MDB.php
if ($this->verifyPassword(trim($password),
trim($res[$this->options['passwordcol']]),
$this->options['cryptType'])) {
Expected result:
----------------
The user should be authenticated.
Should be validating MD5('test ') not MD5('test')
------------------------------------------------------------------------
--
Edit this bug report at http://pear.php.net/bugs/bug.php?id=76&edit=1