Edit report at https://bugs.php.net/bug.php?id=68776&edit=1
ID: 68776
Updated by: yohgaki@php.net
Reported by: yohgaki@php.net
Summary: mail() does not have mail header injection
prevention for additional headers
Status: Closed
Type: Bug
Package: Mail related
Operating System: any
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
@chaos
To send multipart MIME message, users should use header and body correctly. RFC 2822 defines
CRLF+CRLF as start of body. So if users are misusing $additional_headers, they have to fix their
code.
Previous Comments:
------------------------------------------------------------------------
[2015-06-25 04:21:52] yohgaki@php.net
@chaos
We are planning to eliminate injection by this
https://bugs.php.net/bug.php?id=69791
------------------------------------------------------------------------
[2015-06-24 15:10:53] chaos at isocity dot de
Thx for response.
A short feedback here:
<?php
//Example mail with HMTL body on additional_header
$uid = md5(rand());
$to = "example@example.com";
$subject = "My subject";
$headers =
"From: webmaster@example.com" . "\r\n" .
"MIME-Version: 1.0" . "\r\n" .
"Content-Type: multipart/mixed; boundary=\"".$uid."\"" .
"\r\n" .
"This is a multi-part message in MIME format." . "\r\n" .
"--".$uid . "\r\n" .
"Content-Type: TEXT/html; CHARSET=iso-8859-1" . "\r\n" .
"Content-Transfer-Encoding: BASE64" . "\r\n" .
"Content-Description: htmlpart" . "\r\n" .
"" . "\r\n" .
"=?UTF-8?B?PHN0cm9uZz50ZXN0PC9zdHJvbmc+?=" . "\r\n" .
"--".$uid;
mail($to,$subject,'',$headers);
?>
Warning: mail(): Multiple or malformed newlines found in additional_header in /
It seems like it doesn't matter how to perform $additional_headers if something like
attachments or html-body-parts are set up.
Addition: If this line: "". "\r\n" . is been removed, the mail()-error
doesn't apply. But unfortunately either no email is sent this way on one hosting plattform or
the email is sent without body on the other.
------------------------------------------------------------------------
[2015-06-24 01:33:26] yohgaki@php.net
Done.
http://svn.php.net/viewvc?view=revision&revision=337039
Please feel free to improve anything.
------------------------------------------------------------------------
[2015-06-23 21:23:13] yohgaki@php.net
@cmb
I agree. Documentation must be improved.
I'll update the doc.
------------------------------------------------------------------------
[2015-06-23 20:03:30] cmb@php.net
Yasuo, I assume that fixing bug #69791 will not make it possible
to pass the result of imap_mail_compose() as $additional_headers
parameter of mail(). Actually, I consider passing the body of a
mail via $additional_headers as more than doubtful.
However, the current documentation doesn't explicitly state that
this could not be done, and apparently it worked before the fix of
this bug had been applied. So this is a BC, albeit likely a very
minor one; the documentation should better be updated accordingly,
nonetheless.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68776
--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1