#50977 [Fbk->Opn]: imap_headerinfo Address buffer overflow
| From: | lokitek at gmail dot com | Date: | Wed, 10 Feb 2010 16:06:17 +0000 |
| Subject: | #50977 [Fbk->Opn]: imap_headerinfo Address buffer overflow | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-147397@lists.php.net to get a copy of this message | ||
ID: 50977
User updated by: lokitek at gmail dot com
Reported By: lokitek at gmail dot com
-Status: Feedback
+Status: Open
Bug Type: Reproducible crash
Operating System: CentOS 5.4
PHP Version: 5.2.12
New Comment:
The c-client library is:
libc-client 2004g-2.2.1
2004 sounds somewhat old, should I try to find an upgrade for it?
Previous Comments:
------------------------------------------------------------------------
[2010-02-10 00:16:36] pajoye@php.net
I'm not asking which PHP version you use (try 5.2.12, instead of
5.2.11) but which c-client library you use. c-client is the imap library
used by the php imap extension.
------------------------------------------------------------------------
[2010-02-10 00:12:41] lokitek at gmail dot com
I don't think that it makes a huge difference, but I just realized that
I'm on php-5.2.11 and using php-imap-5.2.11
If this isn't what you're after, just let me know and I can do a bit of
debugging all around.
Thanks!
------------------------------------------------------------------------
[2010-02-09 19:06:57] pajoye@php.net
Which imap version do you use?
------------------------------------------------------------------------
[2010-02-09 19:00:23] lokitek at gmail dot com
Description:
------------
While using the imap_headerinfo() function to obtain information about
emails that I check via IMAP, I noticed that PHP complained about
imap_headerinfo() Address buffer overflow.
A bit of investigation revealed that a spam message containing 500+ CC
email addresses caused this issue.
Reproduce code:
---------------
// Send an email with 500+ CCd users. then use imap_headerinfo() to //
obtain all header information.
// [from doc]
$mBox = imap_open("{host:143/imap/novalidate-cert}INBOX}", $username,
$password); // open as imap
$header = imap_header($mBox, 1); // get first mails header
// imap_headerinfo() will crash with the following error:
// PHP Fatal error: imap_headerinfo(): Address buffer overflow
Expected result:
----------------
I expect to information about the given message number by reading its
headers and returned in an object format
Actual result:
--------------
PHP Fatal error: imap_headerinfo(): Address buffer overflow
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=50977&edit=1