Bug #73203 [Opn->Ver]: passing additional_parameters causes mail to fail
| From: | cmb@php.net | Date: | Fri, 30 Sep 2016 08:21:11 +0000 |
| Subject: | Bug #73203 [Opn->Ver]: passing additional_parameters causes mail to fail | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-204358@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73203&edit=1
ID: 73203
Updated by: cmb@php.net
Reported by: mberchtold at gmail dot com
Summary: passing additional_parameters causes mail to fail
-Status: Open
+Status: Verified
Type: Bug
Package: Mail related
Operating System: Windows
PHP Version: 7.1.0RC3
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Indeed, if $additional_parameters is empty an unsigned underflow
occurs, causing this error message.
Previous Comments:
------------------------------------------------------------------------
[2016-09-29 20:46:07] mberchtold at gmail dot com
Description:
------------
Problem
=======
mail throws this fatal error if an additional_parameters (even if it is an empty string) is passed
to the function:
PHP Fatal error: mail(): Escaped command exceeds the allowed length of 8192 bytes
Cause
=====
In the mail function, the extra_cmd is escaped with php_escape_shell_cmd:
https://github.com/php/php-src/blob/master/ext/standard/mail.c#L374
This is incorrect if the string is not passed to an executable. This is the case on Windows when
SMTP is used (php.ini: mail.SMTP).
Solution
========
The additional_parameters argument should be ignored (and therefore not be escaped) if it is not
used (not passed to a shell command).
Also there seems to be another bug where php_escape_shell_cmd fails if an empty string is passed.
Test script:
---------------
mail("test@test.com", "subject", "message", "From:
lala@test.com", "");
Actual result:
--------------
PHP Fatal error: mail(): Escaped command exceeds the allowed length of 8192 bytes
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73203&edit=1