Bug #68776 [Asn->Csd]: mail() does not have mail header injection prevention for additional headers

From: Date: Wed, 10 Jun 2015 04:35:58 +0000
Subject: Bug #68776 [Asn->Csd]: mail() does not have mail header injection prevention for additional headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193271@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1 ID: 68776 Updated by: stas@php.net Reported by: yohgaki@php.net Summary: mail() does not have mail header injection prevention for additional headers -Status: Assigned +Status: Closed Type: Bug Package: Mail related Operating System: any PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N New Comment: Automatic comment on behalf of yohgaki Revision: http://git.php.net/?p=php-src.git;a=commit;h=9d168b863e007c4e15ebe4d2eecabdf8b0582e30 Log: Fixed bug #68776 Previous Comments: ------------------------------------------------------------------------ [2015-06-01 01:12:38] stas@php.net Please see my comments in git. ------------------------------------------------------------------------ [2015-01-25 03:00:47] yohgaki@php.net @cmbecker69 Thanks. Sloppy reading the code. I'll fix it anyway. ------------------------------------------------------------------------ [2015-01-17 18:40:29] cmbecker69 at gmx dot de When passing unvalidated and unsanitized input as $additional_headers argument, both functions are vulnerable to email header injection. For instance: // $_POST['from'] == "me@example.com\r\nBcc: her@example.com" $from = $_POST['from']; mb_send_mail( 'you@example.com', 'foo', 'bar', "From: $from" ); It seems to me that this is more of an documentation issue. ------------------------------------------------------------------------ [2015-01-09 09:59:00] yohgaki@php.net Description: ------------ mb_send_mail() parses additional headers and stores into hash. During the parse process, invalid headers are discarded. However, mail() simply check \0 and strip trailing \r\n. Therefore, mail() is vulnerable to mail header injections via additional header parameter. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1

« previous php.bugs (#193271) next »