Bug #68776 [Asn->Csd]: mail() does not have mail header injection prevention for additional headers
| From: | stas@php.net | Date: | Wed, 10 Jun 2015 04:35:58 +0000 |
| Subject: | Bug #68776 [Asn->Csd]: mail() does not have mail header injection prevention for additional headers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193271@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1
ID: 68776
Updated by: stas@php.net
Reported by: yohgaki@php.net
Summary: mail() does not have mail header injection
prevention for additional headers
-Status: Assigned
+Status: Closed
Type: Bug
Package: Mail related
Operating System: any
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=9d168b863e007c4e15ebe4d2eecabdf8b0582e30
Log: Fixed bug #68776
Previous Comments:
------------------------------------------------------------------------
[2015-06-01 01:12:38] stas@php.net
Please see my comments in git.
------------------------------------------------------------------------
[2015-01-25 03:00:47] yohgaki@php.net
@cmbecker69 Thanks. Sloppy reading the code.
I'll fix it anyway.
------------------------------------------------------------------------
[2015-01-17 18:40:29] cmbecker69 at gmx dot de
When passing unvalidated and unsanitized input as
$additional_headers argument, both functions are vulnerable to
email header injection. For instance:
// $_POST['from'] == "me@example.com\r\nBcc: her@example.com"
$from = $_POST['from'];
mb_send_mail(
'you@example.com', 'foo', 'bar', "From: $from"
);
It seems to me that this is more of an documentation issue.
------------------------------------------------------------------------
[2015-01-09 09:59:00] yohgaki@php.net
Description:
------------
mb_send_mail() parses additional headers and stores into hash. During the parse process, invalid
headers are discarded.
However, mail() simply check \0 and strip trailing \r\n. Therefore, mail() is vulnerable to mail
header injections via additional header parameter.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1