Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers

From: Date: Wed, 02 Sep 2015 13:18:52 +0000
Subject: Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-195702@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1

 ID:                 68776
 Comment by:         merijn at web2all dot nl
 Reported by:        yohgaki@php.net
 Summary:            mail() does not have mail header injection
                     prevention for additional headers
 Status:             Closed
 Type:               Bug
 Package:            Mail related
 Operating System:   any
 PHP Version:        Irrelevant
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

@yohgaki

regarding your last comment @chaos; 
The documentation states 'String to be inserted at the end of the email header' and it
could (and has) been used to send a MIME message. 
So this injection prevention fix breaks code which worked for over 10 years. And its also in a
pretty important part, the sending of mail.

I think this should not be fixed in minor release without any mention of a serious backwards
compatibility break....


Previous Comments:
------------------------------------------------------------------------
[2015-06-25 04:24:56] yohgaki@php.net

@chaos

To send multipart MIME message, users should use header and body correctly. RFC 2822 defines
CRLF+CRLF as start of body. So if users are misusing $additional_headers, they have to fix their
code.

------------------------------------------------------------------------
[2015-06-25 04:21:52] yohgaki@php.net

@chaos

We are planning to eliminate injection by this
https://bugs.php.net/bug.php?id=69791

------------------------------------------------------------------------
[2015-06-24 15:10:53] chaos at isocity dot de

Thx for response.

A short feedback here:

<?php

//Example mail with HMTL body on additional_header
$uid = md5(rand());

$to = "example@example.com";
$subject = "My subject";

$headers = 

"From: webmaster@example.com" 				. "\r\n" .

"MIME-Version: 1.0" 					. "\r\n" .
"Content-Type: multipart/mixed; boundary=\"".$uid."\""	.
"\r\n" .
"This is a multi-part message in MIME format." 		. "\r\n" .
"--".$uid						. "\r\n" .
"Content-Type: TEXT/html; CHARSET=iso-8859-1" 		. "\r\n" .
"Content-Transfer-Encoding: BASE64" 			. "\r\n" .
"Content-Description: htmlpart" 			. "\r\n" .
"" 							. "\r\n" .
"=?UTF-8?B?PHN0cm9uZz50ZXN0PC9zdHJvbmc+?=" 		. "\r\n" .
"--".$uid;

mail($to,$subject,'',$headers);

?>

Warning: mail(): Multiple or malformed newlines found in additional_header in /

It seems like it doesn't matter how to perform $additional_headers if something like
attachments or html-body-parts are set up.

Addition: If this line: "". "\r\n" . is been removed, the mail()-error
doesn't apply. But unfortunately either no email is sent this way on one hosting plattform or
the email is sent without body on the other.

------------------------------------------------------------------------
[2015-06-24 01:33:26] yohgaki@php.net

Done.

http://svn.php.net/viewvc?view=revision&revision=337039

Please feel free to improve anything.

------------------------------------------------------------------------
[2015-06-23 21:23:13] yohgaki@php.net

@cmb

I agree. Documentation must be improved. 
I'll update the doc.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=68776


--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1


Thread (16 messages)

« previous php.bugs (#195702) next »