Bug #68776 [Asn]: mail() does not have mail header injection prevention for additional headers
From: stas@php.net Date: Mon, 01 Jun 2015 01:12:39 +0000 Subject: Bug #68776 [Asn]: mail() does not have mail header injection prevention for additional headers References: 1 Groups: php.bugs Request: Send a blank email to php-bugs+get-193044@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1
ID: 68776
Updated by: stas@php.net
Reported by: yohgaki@php.net
Summary: mail() does not have mail header injection
prevention for additional headers
Status: Assigned
Type: Bug
Package: Mail related
Operating System: any
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Please see my comments in git.
Previous Comments:
------------------------------------------------------------------------
[2015-01-25 03:00:47] yohgaki@php.net
@cmbecker69 Thanks. Sloppy reading the code.
I'll fix it anyway.
------------------------------------------------------------------------
[2015-01-17 18:40:29] cmbecker69 at gmx dot de
When passing unvalidated and unsanitized input as
$additional_headers argument, both functions are vulnerable to
email header injection. For instance:
// $_POST['from'] == "me@example.com\r\nBcc: her@example.com"
$from = $_POST['from'];
mb_send_mail(
'you@example.com', 'foo', 'bar', "From: $from"
);
It seems to me that this is more of an documentation issue.
------------------------------------------------------------------------
[2015-01-09 09:59:00] yohgaki@php.net
Description:
------------
mb_send_mail() parses additional headers and stores into hash. During the parse process, invalid
headers are discarded.
However, mail() simply check \0 and strip trailing \r\n. Therefore, mail() is vulnerable to mail
header injections via additional header parameter.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1
Thread (16 messages)
- Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Asn]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Asn]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Asn->Csd]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
- Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
| « previous | php.bugs (#193044) | next » |
|---|