Bug #28038 [Com]: Sent incorrect RCPT TO commands to SMTP server

From: Date: Fri, 31 Jan 2014 21:51:30 +0000
Subject: Bug #28038 [Com]: Sent incorrect RCPT TO commands to SMTP server
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184107@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=28038&edit=1

 ID:                 28038
 Comment by:         ka30r dot 2014 at gmail dot com
 Reported by:        jordi at jcanals dot net
 Summary:            Sent incorrect RCPT TO commands to SMTP server
 Status:             Closed
 Type:               Bug
 Package:            Mail related
 Operating System:   win32 only
 PHP Version:        5.*, 6SVN
 Assigned To:        garretts
 Block user comment: N
 Private report:     N

 New Comment:

سلام این یه تست هستش


Previous Comments:
------------------------------------------------------------------------
[2009-08-26 21:59:54] svn@php.net

Automatic comment from SVN on behalf of pajoye
Revision: http://svn.php.net/viewvc/?view=revision&revision=287783
Log: - silent warning (fix for #28038)

------------------------------------------------------------------------
[2009-08-19 11:30:01] jani@php.net

According to the commit, this is fixed in all branches. So fix will be in upcoming 5.2.11 release as
well, not only 5.3.1.

------------------------------------------------------------------------
[2009-08-18 18:58:33] svn@php.net

Automatic comment from SVN on behalf of garretts
Revision: http://svn.php.net/viewvc/?view=revision&revision=287462
Log: - Fixed bug #28038 (Sent incorrect RCPT TO commands to SMTP server)

------------------------------------------------------------------------
[2009-08-18 18:50:45] garretts@php.net

I've fixed this in PHP-5.3.1-dev.

I added in code to use the contents between angle brackets < > if there is a pair of angle
brackets passed in.

If the angle brackets are not passed in as a pair, this patch doesn't alter the contents
(missing one angle bracket is clearly invalid), and should likely be rejected by the SMTP server.

And, for the record SMTP (RFC 2821) doesn't have its addresses defined by RFC 2822 for
"MAIL FROM:" and "RCPT TO:" -- they should be just the undecorated mailbox
address. (see RFC 2821- 4.1.2 Command Argument Syntax)








------------------------------------------------------------------------
[2009-04-06 14:29:44] php at shitware dot nl

I'm no C expert, but wouldn't this provide a quick fix:

instead of:

snprintf(Buffer, MAIL_BUFFER_SIZE, "RCPT TO:<%s>\r\n", token);

use:

snprintf(Buffer, MAIL_BUFFER_SIZE, token[(strlen(token)-1)] == ">" ? "RCPT
TO:%s\r\n" : "RCPT TO:<%s>\r\n", token);

for EVERY use of token (including RPath)?

(plain e-mail addresses are still placed between <...>, formatted e-mail addresses get in the
transaction unaltered)

I tried setting up the Windows build environment to test this, but got lost in the different
how-to's ...

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=28038


-- 
Edit this bug report at https://bugs.php.net/bug.php?id=28038&edit=1


Thread (45 messages)

« previous php.bugs (#184107) next »