Bug #68776 [Asn]: mail() does not have mail header injection prevention for additional headers

From: Date: Mon, 01 Jun 2015 01:12:39 +0000
Subject: Bug #68776 [Asn]: mail() does not have mail header injection prevention for additional headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193044@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1

 ID:                 68776
 Updated by:         stas@php.net
 Reported by:        yohgaki@php.net
 Summary:            mail() does not have mail header injection
                     prevention for additional headers
 Status:             Assigned
 Type:               Bug
 Package:            Mail related
 Operating System:   any
 PHP Version:        Irrelevant
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

Please see my comments in git.


Previous Comments:
------------------------------------------------------------------------
[2015-01-25 03:00:47] yohgaki@php.net

@cmbecker69 Thanks. Sloppy reading the code.

I'll fix it anyway.

------------------------------------------------------------------------
[2015-01-17 18:40:29] cmbecker69 at gmx dot de

When passing unvalidated and unsanitized input as
$additional_headers argument, both functions are vulnerable to
email header injection. For instance:

  // $_POST['from'] == "me@example.com\r\nBcc: her@example.com"
  $from = $_POST['from'];
  mb_send_mail(
    'you@example.com', 'foo', 'bar', "From: $from"
  );
  
It seems to me that this is more of an documentation issue.

------------------------------------------------------------------------
[2015-01-09 09:59:00] yohgaki@php.net

Description:
------------
mb_send_mail() parses additional headers and stores into hash. During the parse process, invalid
headers are discarded.

However, mail() simply check \0 and strip trailing \r\n. Therefore, mail() is vulnerable to mail
header injections via additional header parameter.




------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1


Thread (16 messages)

« previous php.bugs (#193044) next »