Skip to content

Truncate the per-object crypt key to min(n/8+5, 16) bytes - #94

Open
djsnowsill wants to merge 3 commits into
ledongthuc:masterfrom
CalibreFinancialTechnology:rc4-object-key-length
Open

djsnowsill wants to merge 3 commits into
ledongthuc:masterfrom
CalibreFinancialTechnology:rc4-object-key-length

Conversation

@djsnowsill

Copy link
Copy Markdown

Summary

  • cryptKey returned the whole 16-byte MD5 as the per-object key. PDF 32000-1:2008 Algorithm 1 step e takes the first n/8+5 bytes, at most 16. That is 16 for a 128-bit key, so those files read, and 10 for a 40-bit key, so every 40-bit RC4 file opened (the document key and the /U check were right) and then panicked with zlib: invalid header on its first stream.
  • Adds a fixture, a one-line page encrypted by pdfcpu with 40-bit RC4 (/V 1 /R 2) and an empty user password, and a test that fails before the change and passes after it.
  • TestCryptKeyDeterministicAndSaltAware asserted a 16-byte key for a 6-byte document key, which encoded the defect; it now asserts 11, and 16 for a 16-byte key.

Measured on 473 real ASX announcements produced by Adlib (40-bit RC4, empty user password): none read before this change, 20 of 20 sampled read in full after it, matching pdftotext.

Test plan

  • go test ./ green on this branch
  • TestReads40BitRC4WithEmptyUserPassword fails on master, passes here
  • 20 real 40-bit files read in full with the patched reader

PDF 32000-1:2008 Algorithm 1 step e takes the first n/8+5 bytes of the
MD5 (at most 16) as the object key. cryptKey returned the whole digest,
which is right only for a 128-bit key. Every 40-bit RC4 file therefore
opened (the password check uses the document key, which was correct) and
then panicked with "zlib: invalid header" on its first stream.

Two fixtures, the same page encrypted by pdfcpu with RC4 at 40 and 128
bits and an empty user password: the 40-bit one failed before this
change and both read after it.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant