Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers

From: Date: Wed, 24 Jun 2015 15:10:54 +0000
Subject: Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193849@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1 ID: 68776 Comment by: chaos at isocity dot de Reported by: yohgaki@php.net Summary: mail() does not have mail header injection prevention for additional headers Status: Closed Type: Bug Package: Mail related Operating System: any PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N New Comment: Thx for response. A short feedback here: <?php //Example mail with HMTL body on additional_header $uid = md5(rand()); $to = "example@example.com"; $subject = "My subject"; $headers = "From: webmaster@example.com" . "\r\n" . "MIME-Version: 1.0" . "\r\n" . "Content-Type: multipart/mixed; boundary=\"".$uid."\"" . "\r\n" . "This is a multi-part message in MIME format." . "\r\n" . "--".$uid . "\r\n" . "Content-Type: TEXT/html; CHARSET=iso-8859-1" . "\r\n" . "Content-Transfer-Encoding: BASE64" . "\r\n" . "Content-Description: htmlpart" . "\r\n" . "" . "\r\n" . "=?UTF-8?B?PHN0cm9uZz50ZXN0PC9zdHJvbmc+?=" . "\r\n" . "--".$uid; mail($to,$subject,'',$headers); ?> Warning: mail(): Multiple or malformed newlines found in additional_header in / It seems like it doesn't matter how to perform $additional_headers if something like attachments or html-body-parts are set up. Addition: If this line: "". "\r\n" . is been removed, the mail()-error doesn't apply. But unfortunately either no email is sent this way on one hosting plattform or the email is sent without body on the other. Previous Comments: ------------------------------------------------------------------------ [2015-06-24 01:33:26] yohgaki@php.net Done. http://svn.php.net/viewvc?view=revision&revision=337039 Please feel free to improve anything. ------------------------------------------------------------------------ [2015-06-23 21:23:13] yohgaki@php.net @cmb I agree. Documentation must be improved. I'll update the doc. ------------------------------------------------------------------------ [2015-06-23 20:03:30] cmb@php.net Yasuo, I assume that fixing bug #69791 will not make it possible to pass the result of imap_mail_compose() as $additional_headers parameter of mail(). Actually, I consider passing the body of a mail via $additional_headers as more than doubtful. However, the current documentation doesn't explicitly state that this could not be done, and apparently it worked before the fix of this bug had been applied. So this is a BC, albeit likely a very minor one; the documentation should better be updated accordingly, nonetheless. ------------------------------------------------------------------------ [2015-06-23 11:49:07] yohgaki@php.net We are aware of that. I'm going to handle it. https://bugs.php.net/bug.php?id=69791 ------------------------------------------------------------------------ [2015-06-23 09:45:00] chaos at isocity dot de Now it has issues with: mail('', $subject,'',imap_mail_compose($envelope, $body))); Also this version of code: function validateMail($str){ return str_replace(array('\r\r','\r\0','\r\n\r\n','\n\n','\n\0'),'',$str); } mail('', $subject,'',validateMail(imap_mail_compose($envelope, $body)))); ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68776 -- Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1

« previous php.bugs (#193849) next »