Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers

From: Date: Sat, 17 Jan 2015 18:40:29 +0000
Subject: Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190004@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1

 ID:                 68776
 Comment by:         cmbecker69 at gmx dot de
 Reported by:        yohgaki@php.net
 Summary:            mail() does not have mail header injection
                     prevention for additional headers
 Status:             Open
 Type:               Bug
 Package:            Mail related
 Operating System:   any
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

When passing unvalidated and unsanitized input as
$additional_headers argument, both functions are vulnerable to
email header injection. For instance:

  // $_POST['from'] == "me@example.com\r\nBcc: her@example.com"
  $from = $_POST['from'];
  mb_send_mail(
    'you@example.com', 'foo', 'bar', "From: $from"
  );
  
It seems to me that this is more of an documentation issue.


Previous Comments:
------------------------------------------------------------------------
[2015-01-09 09:59:00] yohgaki@php.net

Description:
------------
mb_send_mail() parses additional headers and stores into hash. During the parse process, invalid
headers are discarded.

However, mail() simply check \0 and strip trailing \r\n. Therefore, mail() is vulnerable to mail
header injections via additional header parameter.




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1


Thread (16 messages)

« previous php.bugs (#190004) next »