Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
| From: | chaos at isocity dot de | Date: | Wed, 24 Jun 2015 15:10:54 +0000 |
| Subject: | Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193849@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1
ID: 68776
Comment by: chaos at isocity dot de
Reported by: yohgaki@php.net
Summary: mail() does not have mail header injection
prevention for additional headers
Status: Closed
Type: Bug
Package: Mail related
Operating System: any
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Thx for response.
A short feedback here:
<?php
//Example mail with HMTL body on additional_header
$uid = md5(rand());
$to = "example@example.com";
$subject = "My subject";
$headers =
"From: webmaster@example.com" . "\r\n" .
"MIME-Version: 1.0" . "\r\n" .
"Content-Type: multipart/mixed; boundary=\"".$uid."\"" .
"\r\n" .
"This is a multi-part message in MIME format." . "\r\n" .
"--".$uid . "\r\n" .
"Content-Type: TEXT/html; CHARSET=iso-8859-1" . "\r\n" .
"Content-Transfer-Encoding: BASE64" . "\r\n" .
"Content-Description: htmlpart" . "\r\n" .
"" . "\r\n" .
"=?UTF-8?B?PHN0cm9uZz50ZXN0PC9zdHJvbmc+?=" . "\r\n" .
"--".$uid;
mail($to,$subject,'',$headers);
?>
Warning: mail(): Multiple or malformed newlines found in additional_header in /
It seems like it doesn't matter how to perform $additional_headers if something like
attachments or html-body-parts are set up.
Addition: If this line: "". "\r\n" . is been removed, the mail()-error
doesn't apply. But unfortunately either no email is sent this way on one hosting plattform or
the email is sent without body on the other.
Previous Comments:
------------------------------------------------------------------------
[2015-06-24 01:33:26] yohgaki@php.net
Done.
http://svn.php.net/viewvc?view=revision&revision=337039
Please feel free to improve anything.
------------------------------------------------------------------------
[2015-06-23 21:23:13] yohgaki@php.net
@cmb
I agree. Documentation must be improved.
I'll update the doc.
------------------------------------------------------------------------
[2015-06-23 20:03:30] cmb@php.net
Yasuo, I assume that fixing bug #69791 will not make it possible
to pass the result of imap_mail_compose() as $additional_headers
parameter of mail(). Actually, I consider passing the body of a
mail via $additional_headers as more than doubtful.
However, the current documentation doesn't explicitly state that
this could not be done, and apparently it worked before the fix of
this bug had been applied. So this is a BC, albeit likely a very
minor one; the documentation should better be updated accordingly,
nonetheless.
------------------------------------------------------------------------
[2015-06-23 11:49:07] yohgaki@php.net
We are aware of that.
I'm going to handle it.
https://bugs.php.net/bug.php?id=69791
------------------------------------------------------------------------
[2015-06-23 09:45:00] chaos at isocity dot de
Now it has issues with:
mail('', $subject,'',imap_mail_compose($envelope, $body)));
Also this version of code:
function validateMail($str){
return
str_replace(array('\r\r','\r\0','\r\n\r\n','\n\n','\n\0'),'',$str);
}
mail('', $subject,'',validateMail(imap_mail_compose($envelope, $body))));
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68776
--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1