#76 [Opn->Csd]: A password of "test<space>" is not validated

From: Date: Mon, 13 Oct 2003 08:10:54 +0000
Subject: #76 [Opn->Csd]: A password of "test<space>" is not validated
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-22631@lists.php.net to get a copy of this message
ID: 76 Updated by: yavo@php.net Reported By: php at untz dot cx -Status: Open +Status: Closed Bug Type: Auth Operating System: win2k PHP Version: 4.3.2 New Comment: This bug has been fixed in CVS. In case this was a documentation problem, the fix will show up at the end of next Sunday (CET) on pear.php.net. In case this was a pear.php.net website problem, the change will show up on the website in short time. Thank you for the report, and for helping us make PEAR better. Fixed bugs in DB and MDB container changed trim($password) to trim($password, "\r\n") to trim only new line and carriage return chars, am not sure if trim is really needed there thou. Yavo Previous Comments: ------------------------------------------------------------------------ [2003-10-07 09:40:57] php at untz dot cx Description: ------------ Due to $password being trim()'d before being validated, a password that begins or ends in a space (or any whitespace) is not validated correctly. The second trim is alright if using MD5() crypting, but will cause problems if using no crypting. ie $password1 == $password2 Reproduce code: --------------- http://cvs.php.net/annotate.php/pear/Auth/Container/DB.php?rev=1.38 Line 256 of DB.php and similar in MDB.php if ($this->verifyPassword(trim($password), trim($res[$this->options['passwordcol']]), $this->options['cryptType'])) { Expected result: ---------------- The user should be authenticated. Should be validating MD5('test ') not MD5('test') ------------------------------------------------------------------------ -- Edit this bug report at http://pear.php.net/bugs/bug.php?id=76&edit=1

« previous php.pear.dev (#22631) next »