Bug #70145 [Ana->Csd]: From field incorrectly parsed from headers
| From: | ab@php.net | Date: | Wed, 19 Aug 2015 09:08:27 +0000 |
| Subject: | Bug #70145 [Ana->Csd]: From field incorrectly parsed from headers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-195329@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=70145&edit=1
ID: 70145
Updated by: ab@php.net
Reported by: mberchtold at gmail dot com
Summary: From field incorrectly parsed from headers
-Status: Analyzed
+Status: Closed
Type: Bug
Package: Mail related
Operating System: Windows
PHP Version: 7.0.0beta2
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=0562ec85df659dc3675ca26bec102b30ab25329d
Log: Fix bug #70145 From field incorrectly parsed from headers
Previous Comments:
------------------------------------------------------------------------
[2015-07-27 13:02:00] cmb@php.net
Indeed, the algorithm is too limited. We'd need to loop over
headers_lc looking for additional potetential From header fields.
------------------------------------------------------------------------
[2015-07-27 00:49:25] mberchtold at gmail dot com
The bug is here:
https://github.com/php/php-src/blob/master/win32/sendmail.c#L245
} else if ( headers_lc &&
(pos1 = strstr(headers_lc->val, "from:")) &&
((pos1 == headers_lc->val) || (*(pos1-1) == '\n'))
) {
------------------------------------------------------------------------
[2015-07-27 00:43:17] mberchtold at gmail dot com
Description:
------------
the mail function incorrectly parses the From field from the headers.
For example the when passing the following headers:
$headers = "DKIM-Signature: v=1; a=rsa-sha1; bh=ZOokPFyLIFHFdZq7e/+JaJ+LVDI=; c=relaxed;
d=test.com; h=from:to:subject; s=mail;
Date: Mon, 27 Jul 2015 00:24:55 +0000
From: =?UTF-8?Q?test?= <sales@test.com>
To: mb@test.com";
the mail function fails and logs the following warning:
PHP Warning: mail(): "sendmail_from" not set in php.ini or custom
"From:" header missing in test.php on line 1
The problem seems to be that the mail implementation is confused by the extra from in the first
header:
h=from:to:subject; s=mail;
Test script:
---------------
// reproduces the bug
mail("mb@test.com", "subject", "message1", "DKIM-Signature: v=1;
a=rsa-sha1; bh=ZOokPFyLIFHFdZq7e/+JaJ+LVDI=; c=relaxed; d=test.com; h=from:to:subject; s=mail;
Date: Mon, 27 Jul 2015 00:24:55 +0000
From: =?UTF-8?Q?test?= <sales@test.com>
To: mb@test.com");
// does not reproduce the bug
mail("mb@test.com", "subject", "message1", "DKIM-Signature: v=1;
a=rsa-sha1; bh=ZOokPFyLIFHFdZq7e/+JaJ+LVDI=; c=relaxed; d=test.com;
Date: Mon, 27 Jul 2015 00:24:55 +0000
From: =?UTF-8?Q?test?= <sales@test.com>
To: mb@test.com");
Expected result:
----------------
no warning
Actual result:
--------------
PHP Warning: mail(): "sendmail_from" not set in php.ini or custom
"From:" header missing in test.php on line 1
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70145&edit=1