#17568 [Opn->Csd]: Fifth parameter doesn't work correct
| From: | mfischer@php.net | Date: | Mon, 26 Aug 2002 23:32:43 +0000 |
| Subject: | #17568 [Opn->Csd]: Fifth parameter doesn't work correct | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-17892@lists.php.net to get a copy of this message | ||
ID: 17568
Updated by: mfischer@php.net
Reported By: ruudb@stress.utwente.nl
-Status: Open
+Status: Closed
Bug Type: Mail related
Operating System: Debian GNU/Linux 2.2
PHP Version: 4.2.1
New Comment:
This bug has been fixed in CVS.
In case this was a PHP problem, snapshots of the sources are packaged
every three hours; this change will be in the next snapshot. You can
grab the snapshot at http://snaps.php.net/.
In case this was a documentation problem, the fix will show up soon at
http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites in short time.
Thank you for the report, and for helping us make PHP better.
Kudos to Derick, he fixed the issue.
Basically, if safe_mode is on, the fifth parameter is prohibited. If
it's off, it now should work with spaces to (right Derick?), closing.
Previous Comments:
------------------------------------------------------------------------
[2002-06-02 18:40:05] derick@php.net
Not allowing a space is not totally true. The parameter is escaped
accoding the rules of shell_escape (which add's ' around the script and
escapes existing ''s).
Derick
------------------------------------------------------------------------
[2002-06-02 18:38:56] mfischer@php.net
I don't like this behaviour either but there are some pretty security
concerns here. Maybe this can be sorted out, but I can't tell you
anything right now. Don't count on this being changed soon.
------------------------------------------------------------------------
[2002-06-02 18:36:11] ruudb@stress.utwente.nl
Thanks for your extremely fast answer. Anyway, it is a real problem in
that case. From the sendmail docs: "Note that there _must_ be a space
between the letter 'O' and the name of the option."
Btw, the combination of these two options worked in the 4.0.5/4.0.6
version of PHP.
------------------------------------------------------------------------
[2002-06-02 18:31:47] mfischer@php.net
The fifth one doesn't work because it contains a space. Only one
parameter without space is allowed currently . . .
------------------------------------------------------------------------
[2002-06-02 18:24:21] ruudb@stress.utwente.nl
A small scripting part:
--=[ CUT ]=--
$params="-f".$userinfo[$i][sa_email]." -O deliverymode=q";
mail($to, $subject, $message, $header, $params);
--=[ CUT ]=--
This used to work in the PHP 4.0.6 version, but since 4.1.0 this
results in sendmail errors:
Jun 2 23:49:38 iBBS-01 sendmail[2930]: XAA02930:
to=removed.address@stress.utwente.nl -O deliverymode=q, delay=00:00:00,
xdelay=00
:00:00, mailer=esmtp, relay=stress.utwente.nl.-o.deliverymode=q,
stat=Host unknown (Name server: stress.utwente.nl.-o.delivery
mode=q: host not found)
I think the sequence in which paramters are offered to sendmail has
changed from PHP 4.0.6 to PHP 4.1.0. The problem still persists in PHP
4.2.1.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=17568&edit=1