#19307 [NEW]: ASCII control char injection "fix" in mail()
| From: | mbr at freebsd dot org | Date: | Mon, 09 Sep 2002 11:48:55 +0000 |
| Subject: | #19307 [NEW]: ASCII control char injection "fix" in mail() | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-18757@lists.php.net to get a copy of this message | ||
From: mbr@freebsd.org
Operating system: FreeBSD
PHP version: 4.2.3
PHP Bug Type: Mail related
Bug description: ASCII control char injection "fix" in mail()
In 4.2.3 the ASCII control char injection in the 5th parameter to sendmail
got fixed, that means it got disabled if a user is using the securemode.
Of course this is a important thing to do, but we use the -f parameter of
sendmail, so disable it completly is not an option.
mail($emailto, $titel, $text, "From: $emailfrom\nReply-To:
$emailfrom\nContent-Type: text/plain;
charset=iso-8859-1\nContent-Transfer-Encoding: 8bit", "-f$emailfrom");
So my question is if you could enable just -f mailadress, and verify if it
is a mail-
adress and reject all other things.
Martin
Martin Blapp, <mb@imp.ch> <mbr@FreeBSD.org>
------------------------------------------------------------------
ImproWare AG, UNIXSP & ISP, Zurlindenstrasse 29, 4133 Pratteln, CH
Phone: +41 061 826 93 00: +41 61 826 93 01
PGP: <finger -l mbr@freebsd.org>
PGP Fingerprint: B434 53FC C87C FE7B 0A18 B84C 8686 EF22 D300 551E
------------------------------------------------------------------
--
Edit bug report at http://bugs.php.net/?id=19307&edit=1
--
Try a CVS snapshot: http://bugs.php.net/fix.php?id=19307&r=trysnapshot
Fixed in CVS: http://bugs.php.net/fix.php?id=19307&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=19307&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=19307&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=19307&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=19307&r=support
Expected behavior: http://bugs.php.net/fix.php?id=19307&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=19307&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=19307&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=19307&r=globals