Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers

From: Date: Thu, 25 Jun 2015 04:24:57 +0000
Subject: Bug #68776 [Csd]: mail() does not have mail header injection prevention for additional headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193861@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1

 ID:                 68776
 Updated by:         yohgaki@php.net
 Reported by:        yohgaki@php.net
 Summary:            mail() does not have mail header injection
                     prevention for additional headers
 Status:             Closed
 Type:               Bug
 Package:            Mail related
 Operating System:   any
 PHP Version:        Irrelevant
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

@chaos

To send multipart MIME message, users should use header and body correctly. RFC 2822 defines
CRLF+CRLF as start of body. So if users are misusing $additional_headers, they have to fix their
code.


Previous Comments:
------------------------------------------------------------------------
[2015-06-25 04:21:52] yohgaki@php.net

@chaos

We are planning to eliminate injection by this
https://bugs.php.net/bug.php?id=69791

------------------------------------------------------------------------
[2015-06-24 15:10:53] chaos at isocity dot de

Thx for response.

A short feedback here:

<?php

//Example mail with HMTL body on additional_header
$uid = md5(rand());

$to = "example@example.com";
$subject = "My subject";

$headers = 

"From: webmaster@example.com" 				. "\r\n" .

"MIME-Version: 1.0" 					. "\r\n" .
"Content-Type: multipart/mixed; boundary=\"".$uid."\""	.
"\r\n" .
"This is a multi-part message in MIME format." 		. "\r\n" .
"--".$uid						. "\r\n" .
"Content-Type: TEXT/html; CHARSET=iso-8859-1" 		. "\r\n" .
"Content-Transfer-Encoding: BASE64" 			. "\r\n" .
"Content-Description: htmlpart" 			. "\r\n" .
"" 							. "\r\n" .
"=?UTF-8?B?PHN0cm9uZz50ZXN0PC9zdHJvbmc+?=" 		. "\r\n" .
"--".$uid;

mail($to,$subject,'',$headers);

?>

Warning: mail(): Multiple or malformed newlines found in additional_header in /

It seems like it doesn't matter how to perform $additional_headers if something like
attachments or html-body-parts are set up.

Addition: If this line: "". "\r\n" . is been removed, the mail()-error
doesn't apply. But unfortunately either no email is sent this way on one hosting plattform or
the email is sent without body on the other.

------------------------------------------------------------------------
[2015-06-24 01:33:26] yohgaki@php.net

Done.

http://svn.php.net/viewvc?view=revision&revision=337039

Please feel free to improve anything.

------------------------------------------------------------------------
[2015-06-23 21:23:13] yohgaki@php.net

@cmb

I agree. Documentation must be improved. 
I'll update the doc.

------------------------------------------------------------------------
[2015-06-23 20:03:30] cmb@php.net

Yasuo, I assume that fixing bug #69791 will not make it possible
to pass the result of imap_mail_compose() as $additional_headers
parameter of mail(). Actually, I consider passing the body of a
mail via $additional_headers as more than doubtful.

However, the current documentation doesn't explicitly state that
this could not be done, and apparently it worked before the fix of
this bug had been applied. So this is a BC, albeit likely a very
minor one; the documentation should better be updated accordingly,
nonetheless.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68776


--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1


Thread (16 messages)

« previous php.bugs (#193861) next »