Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers
| From: | yohgaki@php.net | Date: | Tue, 23 Jun 2015 21:23:14 +0000 |
| Subject: | Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193819@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1
ID: 68776
Updated by: yohgaki@php.net
Reported by: yohgaki@php.net
Summary: mail() does not have mail header injection
prevention for additional headers
Status: Closed
Type: Bug
Package: Mail related
Operating System: any
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
@cmb
I agree. Documentation must be improved.
I'll update the doc.
Previous Comments:
------------------------------------------------------------------------
[2015-06-23 20:03:30] cmb@php.net
Yasuo, I assume that fixing bug #69791 will not make it possible
to pass the result of imap_mail_compose() as $additional_headers
parameter of mail(). Actually, I consider passing the body of a
mail via $additional_headers as more than doubtful.
However, the current documentation doesn't explicitly state that
this could not be done, and apparently it worked before the fix of
this bug had been applied. So this is a BC, albeit likely a very
minor one; the documentation should better be updated accordingly,
nonetheless.
------------------------------------------------------------------------
[2015-06-23 11:49:07] yohgaki@php.net
We are aware of that.
I'm going to handle it.
https://bugs.php.net/bug.php?id=69791
------------------------------------------------------------------------
[2015-06-23 09:45:00] chaos at isocity dot de
Now it has issues with:
mail('', $subject,'',imap_mail_compose($envelope, $body)));
Also this version of code:
function validateMail($str){
return
str_replace(array('\r\r','\r\0','\r\n\r\n','\n\n','\n\0'),'',$str);
}
mail('', $subject,'',validateMail(imap_mail_compose($envelope, $body))));
------------------------------------------------------------------------
[2015-06-10 09:15:19] jpauli@php.net
Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=4bf3f646eea270d93ef6b9ebcf285c77a70a733b
Log: Fixed bug #68776
------------------------------------------------------------------------
[2015-06-10 08:50:55] tyrael@php.net
Automatic comment on behalf of yohgaki
Revision: http://git.php.net/?p=php-src.git;a=commit;h=9d168b863e007c4e15ebe4d2eecabdf8b0582e30
Log: Fixed bug #68776
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68776
--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1