Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion composer.json
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@
"pear/pear-core-minimal": "^1.10",
"php-http/guzzle7-adapter": "^1.1.0",
"php-opencloud/openstack": "^3.17",
"phpseclib/phpseclib": "^3.0.55",
"phpseclib/phpseclib": "^3.0.57",
"pimple/pimple": "^3.6.2",
"predis/predis": "^3.4.2",
"psr/clock": "^1.0",
Expand Down
14 changes: 7 additions & 7 deletions composer.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

14 changes: 7 additions & 7 deletions composer/installed.json
Original file line number Diff line number Diff line change
Expand Up @@ -3139,17 +3139,17 @@
},
{
"name": "phpseclib/phpseclib",
"version": "3.0.55",
"version_normalized": "3.0.55.0",
"version": "3.0.57",
"version_normalized": "3.0.57.0",
"source": {
"type": "git",
"url": "https://github.com/phpseclib/phpseclib.git",
"reference": "db9744e6d47e742b1f974e965ad49bdd041105af"
"reference": "d17e0ddaeaf6f22f7e007cbb437d78792fe2a0e4"
},
"dist": {
"type": "zip",
"url": "https://api.github.com/repos/phpseclib/phpseclib/zipball/db9744e6d47e742b1f974e965ad49bdd041105af",
"reference": "db9744e6d47e742b1f974e965ad49bdd041105af",
"url": "https://api.github.com/repos/phpseclib/phpseclib/zipball/d17e0ddaeaf6f22f7e007cbb437d78792fe2a0e4",
"reference": "d17e0ddaeaf6f22f7e007cbb437d78792fe2a0e4",
"shasum": ""
},
"require": {
Expand All @@ -3167,7 +3167,7 @@
"ext-mcrypt": "Install the Mcrypt extension in order to speed up a few other cryptographic operations.",
"ext-openssl": "Install the OpenSSL extension in order to speed up a wide variety of cryptographic operations."
},
"time": "2026-06-14T23:24:10+00:00",
"time": "2026-08-26T12:13:21+00:00",
"type": "library",
"installation-source": "dist",
"autoload": {
Expand Down Expand Up @@ -3232,7 +3232,7 @@
],
"support": {
"issues": "https://github.com/phpseclib/phpseclib/issues",
"source": "https://github.com/phpseclib/phpseclib/tree/3.0.55"
"source": "https://github.com/phpseclib/phpseclib/tree/3.0.57"
},
"funding": [
{
Expand Down
6 changes: 3 additions & 3 deletions composer/installed.php
Original file line number Diff line number Diff line change
Expand Up @@ -443,9 +443,9 @@
'dev_requirement' => false,
),
'phpseclib/phpseclib' => array(
'pretty_version' => '3.0.55',
'version' => '3.0.55.0',
'reference' => 'db9744e6d47e742b1f974e965ad49bdd041105af',
'pretty_version' => '3.0.57',
'version' => '3.0.57.0',
'reference' => 'd17e0ddaeaf6f22f7e007cbb437d78792fe2a0e4',
'type' => 'library',
'install_path' => __DIR__ . '/../phpseclib/phpseclib',
'aliases' => array(),
Expand Down
2 changes: 1 addition & 1 deletion phpseclib/phpseclib/phpseclib/Crypt/AES.php
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ class AES extends Rijndael
*
* Since \phpseclib3\Crypt\AES extends \phpseclib3\Crypt\Rijndael, this function is, technically, available, but it doesn't do anything.
*
* @see \phpseclib3\Crypt\Rijndael::setBlockLength()
* @see Rijndael::setBlockLength()
* @param int $length
* @throws \BadMethodCallException anytime it's called
*/
Expand Down
6 changes: 3 additions & 3 deletions phpseclib/phpseclib/phpseclib/Crypt/ChaCha20.php
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ class ChaCha20 extends Salsa20
*
* This is mainly just a wrapper to set things up for \phpseclib3\Crypt\Common\SymmetricKey::isValidEngine()
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::__construct()
* @see SymmetricKey::__construct()
* @param int $engine
* @return bool
*/
Expand Down Expand Up @@ -73,7 +73,7 @@ protected function isValidEngineHelper($engine)
/**
* Encrypts a message.
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* @see SymmetricKey::decrypt()
* @see self::crypt()
* @param string $plaintext
* @return string $ciphertext
Expand All @@ -95,7 +95,7 @@ public function encrypt($plaintext)
* $this->decrypt($this->encrypt($plaintext)) == $this->encrypt($this->encrypt($plaintext)).
* At least if the continuous buffer is disabled.
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see SymmetricKey::encrypt()
* @see self::crypt()
* @param string $ciphertext
* @return string $plaintext
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,7 +34,7 @@ abstract class StreamCipher extends SymmetricKey
/**
* Default Constructor.
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::__construct()
* @see SymmetricKey::__construct()
* @return StreamCipher
*/
public function __construct()
Expand Down
54 changes: 27 additions & 27 deletions phpseclib/phpseclib/phpseclib/Crypt/Common/SymmetricKey.php
Original file line number Diff line number Diff line change
Expand Up @@ -60,76 +60,76 @@ abstract class SymmetricKey
* Set to -1 since that's what Crypt/Random.php uses to index the CTR mode.
*
* @link http://en.wikipedia.org/wiki/Block_cipher_modes_of_operation#Counter_.28CTR.29
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* SymmetricKey::encrypt()
* SymmetricKey::decrypt()
*/
const MODE_CTR = -1;
/**
* Encrypt / decrypt using the Electronic Code Book mode.
*
* @link http://en.wikipedia.org/wiki/Block_cipher_modes_of_operation#Electronic_codebook_.28ECB.29
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* SymmetricKey::encrypt()
* SymmetricKey::decrypt()
*/
const MODE_ECB = 1;
/**
* Encrypt / decrypt using the Code Book Chaining mode.
*
* @link http://en.wikipedia.org/wiki/Block_cipher_modes_of_operation#Cipher-block_chaining_.28CBC.29
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* SymmetricKey::encrypt()
* SymmetricKey::decrypt()
*/
const MODE_CBC = 2;
/**
* Encrypt / decrypt using the Cipher Feedback mode.
*
* @link http://en.wikipedia.org/wiki/Block_cipher_modes_of_operation#Cipher_feedback_.28CFB.29
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* SymmetricKey::encrypt()
* SymmetricKey::decrypt()
*/
const MODE_CFB = 3;
/**
* Encrypt / decrypt using the Cipher Feedback mode (8bit)
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* SymmetricKey::encrypt()
* SymmetricKey::decrypt()
*/
const MODE_CFB8 = 7;
/**
* Encrypt / decrypt using the Output Feedback mode (8bit)
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* SymmetricKey::encrypt()
* SymmetricKey::decrypt()
*/
const MODE_OFB8 = 8;
/**
* Encrypt / decrypt using the Output Feedback mode.
*
* @link http://en.wikipedia.org/wiki/Block_cipher_modes_of_operation#Output_feedback_.28OFB.29
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* SymmetricKey::encrypt()
* SymmetricKey::decrypt()
*/
const MODE_OFB = 4;
/**
* Encrypt / decrypt using Galois/Counter mode.
*
* @link https://en.wikipedia.org/wiki/Galois/Counter_Mode
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* SymmetricKey::encrypt()
* SymmetricKey::decrypt()
*/
const MODE_GCM = 5;
/**
* Encrypt / decrypt using streaming mode.
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::encrypt()
* @see \phpseclib3\Crypt\Common\SymmetricKey::decrypt()
* SymmetricKey::encrypt()
* SymmetricKey::decrypt()
*/
const MODE_STREAM = 6;

/**
* Mode Map
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::__construct()
* SymmetricKey::__construct()
*/
const MODE_MAP = [
'ctr' => self::MODE_CTR,
Expand All @@ -146,44 +146,44 @@ abstract class SymmetricKey
/**
* Base value for the internal implementation $engine switch
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::__construct()
* SymmetricKey::__construct()
*/
const ENGINE_INTERNAL = 1;
/**
* Base value for the eval() implementation $engine switch
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::__construct()
* SymmetricKey::__construct()
*/
const ENGINE_EVAL = 2;
/**
* Base value for the mcrypt implementation $engine switch
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::__construct()
* SymmetricKey::__construct()
*/
const ENGINE_MCRYPT = 3;
/**
* Base value for the openssl implementation $engine switch
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::__construct()
* SymmetricKey::__construct()
*/
const ENGINE_OPENSSL = 4;
/**
* Base value for the libsodium implementation $engine switch
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::__construct()
* SymmetricKey::__construct()
*/
const ENGINE_LIBSODIUM = 5;
/**
* Base value for the openssl / gcm implementation $engine switch
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::__construct()
* SymmetricKey::__construct()
*/
const ENGINE_OPENSSL_GCM = 6;

/**
* Engine Reverse Map
*
* @see \phpseclib3\Crypt\Common\SymmetricKey::getEngine()
* SymmetricKey::getEngine()
*/
const ENGINE_MAP = [
self::ENGINE_INTERNAL => 'PHP',
Expand Down Expand Up @@ -1270,7 +1270,7 @@ public function encrypt($plaintext)
if ($this->continuousBuffer) {
$this->encryptIV = $iv;
}
break;
return $ciphertext;
case self::MODE_OFB:
return $this->openssl_ofb_process($plaintext, $this->encryptIV, $this->enbuffer);
}
Expand Down
10 changes: 5 additions & 5 deletions phpseclib/phpseclib/phpseclib/Crypt/DES.php
Original file line number Diff line number Diff line change
Expand Up @@ -53,15 +53,15 @@ class DES extends BlockCipher
/**
* Contains $keys[self::ENCRYPT]
*
* @see \phpseclib3\Crypt\DES::setupKey()
* @see \phpseclib3\Crypt\DES::processBlock()
* @see DES::setupKey()
* @see DES::processBlock()
*/
const ENCRYPT = 0;
/**
* Contains $keys[self::DECRYPT]
*
* @see \phpseclib3\Crypt\DES::setupKey()
* @see \phpseclib3\Crypt\DES::processBlock()
* @see DES::setupKey()
* @see DES::processBlock()
*/
const DECRYPT = 1;

Expand Down Expand Up @@ -1295,7 +1295,7 @@ protected function setupInlineCrypt()
$sbox1 = array_map(["' . self::class . '", "safe_intval"], self::$sbox1);
$sbox2 = array_map(["' . self::class . '", "safe_intval"], self::$sbox2);
$sbox3 = array_map(["' . self::class . '", "safe_intval"], self::$sbox3);
$sbox4 = array_map(["' . self::class .'", "safe_intval"], self::$sbox4);
$sbox4 = array_map(["' . self::class . '", "safe_intval"], self::$sbox4);
$sbox5 = array_map(["' . self::class . '", "safe_intval"], self::$sbox5);
$sbox6 = array_map(["' . self::class . '", "safe_intval"], self::$sbox6);
$sbox7 = array_map(["' . self::class . '", "safe_intval"], self::$sbox7);
Expand Down
20 changes: 14 additions & 6 deletions phpseclib/phpseclib/phpseclib/Crypt/DH.php
Original file line number Diff line number Diff line change
Expand Up @@ -28,14 +28,9 @@
use phpseclib3\Crypt\DH\Parameters;
use phpseclib3\Crypt\DH\PrivateKey;
use phpseclib3\Crypt\DH\PublicKey;
use phpseclib3\Crypt\EC\Curves\Curve25519;
use phpseclib3\Crypt\EC\Curves\Curve448;
use phpseclib3\Crypt\EC\Formats\Keys\PKCS1;
use phpseclib3\Exception\BadConfigurationException;
use phpseclib3\Exception\NoKeyLoadedException;
use phpseclib3\Exception\UnsupportedOperationException;
use phpseclib3\File\ASN1;
use phpseclib3\File\ASN1\Maps;
use phpseclib3\Math\BigInteger;

/**
Expand Down Expand Up @@ -344,8 +339,21 @@ public static function computeSecret($private, $public)
$public = EC::convertPointToPublicKey($curveName, $public, false);
}
$point = $private->multiply($public);
if ($isMontgomeryCurve) {
/*
"Both MAY check, without leaking extra information about the value of K,
whether K is the all-zero value and abort if so"
-- https://datatracker.ietf.org/doc/html/rfc7748#section-6.1 (and #section-6.2)
*/
$size = $curveName == 'Curve25519' ? 32 : 56;
// throw exception if hash_equals is false, otherwise, return $point
if (hash_equals(str_repeat("\0", $size), $point)) {
throw new \UnexpectedValueException('All-zero shared secret detected (points order is too small)');
}
return $point;
}
// according to https://www.secg.org/sec1-v2.pdf#page=33 only X is returned
$secret = $isMontgomeryCurve ? $point : substr($point, 1, (strlen($point) - 1) >> 1);
$secret = substr($point, 1, (strlen($point) - 1) >> 1);
/*
if (($secret[0] & "\x80") === "\x80") {
$secret = "\0$secret";
Expand Down
2 changes: 1 addition & 1 deletion phpseclib/phpseclib/phpseclib/Crypt/DSA/PrivateKey.php
Original file line number Diff line number Diff line change
Expand Up @@ -14,8 +14,8 @@
use phpseclib3\Crypt\Common;
use phpseclib3\Crypt\DSA;
use phpseclib3\Crypt\DSA\Formats\Signature\ASN1 as ASN1Signature;
use phpseclib3\Math\BigInteger;
use phpseclib3\Exception\BadConfigurationException;
use phpseclib3\Math\BigInteger;

/**
* DSA Private Key
Expand Down
2 changes: 1 addition & 1 deletion phpseclib/phpseclib/phpseclib/Crypt/EC.php
Original file line number Diff line number Diff line change
Expand Up @@ -542,7 +542,7 @@ public function getParameters($type = 'PKCS1')
/**
* Determines the signature padding mode
*
* Valid values are: ASN1, SSH2, Raw
* Valid values are: ASN1, IEEE, SSH2, Raw
*
* @param string $format
*/
Expand Down
Loading