Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers

From: Date: Wed, 24 Jun 2015 01:33:27 +0000
Subject: Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193826@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1 ID: 68776 Updated by: yohgaki@php.net Reported by: yohgaki@php.net Summary: mail() does not have mail header injection prevention for additional headers Status: Closed Type: Bug Package: Mail related Operating System: any PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N New Comment: Done. http://svn.php.net/viewvc?view=revision&revision=337039 Please feel free to improve anything. Previous Comments: ------------------------------------------------------------------------ [2015-06-23 21:23:13] yohgaki@php.net @cmb I agree. Documentation must be improved. I'll update the doc. ------------------------------------------------------------------------ [2015-06-23 20:03:30] cmb@php.net Yasuo, I assume that fixing bug #69791 will not make it possible to pass the result of imap_mail_compose() as $additional_headers parameter of mail(). Actually, I consider passing the body of a mail via $additional_headers as more than doubtful. However, the current documentation doesn't explicitly state that this could not be done, and apparently it worked before the fix of this bug had been applied. So this is a BC, albeit likely a very minor one; the documentation should better be updated accordingly, nonetheless. ------------------------------------------------------------------------ [2015-06-23 11:49:07] yohgaki@php.net We are aware of that. I'm going to handle it. https://bugs.php.net/bug.php?id=69791 ------------------------------------------------------------------------ [2015-06-23 09:45:00] chaos at isocity dot de Now it has issues with: mail('', $subject,'',imap_mail_compose($envelope, $body))); Also this version of code: function validateMail($str){ return str_replace(array('\r\r','\r\0','\r\n\r\n','\n\n','\n\0'),'',$str); } mail('', $subject,'',validateMail(imap_mail_compose($envelope, $body)))); ------------------------------------------------------------------------ [2015-06-10 09:15:19] jpauli@php.net Automatic comment on behalf of yohgaki Revision: http://git.php.net/?p=php-src.git;a=commit;h=4bf3f646eea270d93ef6b9ebcf285c77a70a733b Log: Fixed bug #68776 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68776 -- Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1

« previous php.bugs (#193826) next »