#17568 [Opn->Csd]: Fifth parameter doesn't work correct

From: Date: Mon, 26 Aug 2002 23:32:43 +0000
Subject: #17568 [Opn->Csd]: Fifth parameter doesn't work correct
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-17892@lists.php.net to get a copy of this message
ID: 17568 Updated by: mfischer@php.net Reported By: ruudb@stress.utwente.nl -Status: Open +Status: Closed Bug Type: Mail related Operating System: Debian GNU/Linux 2.2 PHP Version: 4.2.1 New Comment: This bug has been fixed in CVS. In case this was a PHP problem, snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. In case this was a documentation problem, the fix will show up soon at http://www.php.net/manual/. In case this was a PHP.net website problem, the change will show up on the PHP.net site and on the mirror sites in short time. Thank you for the report, and for helping us make PHP better. Kudos to Derick, he fixed the issue. Basically, if safe_mode is on, the fifth parameter is prohibited. If it's off, it now should work with spaces to (right Derick?), closing. Previous Comments: ------------------------------------------------------------------------ [2002-06-02 18:40:05] derick@php.net Not allowing a space is not totally true. The parameter is escaped accoding the rules of shell_escape (which add's ' around the script and escapes existing ''s). Derick ------------------------------------------------------------------------ [2002-06-02 18:38:56] mfischer@php.net I don't like this behaviour either but there are some pretty security concerns here. Maybe this can be sorted out, but I can't tell you anything right now. Don't count on this being changed soon. ------------------------------------------------------------------------ [2002-06-02 18:36:11] ruudb@stress.utwente.nl Thanks for your extremely fast answer. Anyway, it is a real problem in that case. From the sendmail docs: "Note that there _must_ be a space between the letter 'O' and the name of the option." Btw, the combination of these two options worked in the 4.0.5/4.0.6 version of PHP. ------------------------------------------------------------------------ [2002-06-02 18:31:47] mfischer@php.net The fifth one doesn't work because it contains a space. Only one parameter without space is allowed currently . . . ------------------------------------------------------------------------ [2002-06-02 18:24:21] ruudb@stress.utwente.nl A small scripting part: --=[ CUT ]=-- $params="-f".$userinfo[$i][sa_email]." -O deliverymode=q"; mail($to, $subject, $message, $header, $params); --=[ CUT ]=-- This used to work in the PHP 4.0.6 version, but since 4.1.0 this results in sendmail errors: Jun 2 23:49:38 iBBS-01 sendmail[2930]: XAA02930: to=removed.address@stress.utwente.nl -O deliverymode=q, delay=00:00:00, xdelay=00 :00:00, mailer=esmtp, relay=stress.utwente.nl.-o.deliverymode=q, stat=Host unknown (Name server: stress.utwente.nl.-o.delivery mode=q: host not found) I think the sequence in which paramters are offered to sendmail has changed from PHP 4.0.6 to PHP 4.1.0. The problem still persists in PHP 4.2.1. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=17568&edit=1

« previous php.bugs (#17892) next »