Bug #73203 [Ver]: passing additional_parameters causes mail to fail

From: Date: Fri, 30 Sep 2016 08:37:59 +0000
Subject: Bug #73203 [Ver]: passing additional_parameters causes mail to fail
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204360@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73203&edit=1 ID: 73203 Updated by: cmb@php.net Reported by: mberchtold at gmail dot com Summary: passing additional_parameters causes mail to fail Status: Verified Type: Bug Package: Mail related Operating System: Windows PHP Version: 7.1.0RC3 Assigned To: cmb Block user comment: N Private report: N New Comment: Yes, I'm already working on this. Actually, mail() isn't the issue, but rather php_escape_shell_cmd() which always fails when called with an empty string. escapeshellcmd() doesn't call php_escape_shell_cmd() when invoked with an empty string, but I think we should fix php_escape_shell_cmd(), because it is PHP_API. Previous Comments: ------------------------------------------------------------------------ [2016-09-30 08:29:59] yohgaki@php.net @cmd Are you working on this? Please don't forget to update PHP_FUNCTION(mb_send_mail), if you modify PHP_FUNCTION(mail). If you are not working on this, I'll. ------------------------------------------------------------------------ [2016-09-30 08:21:10] cmb@php.net Indeed, if $additional_parameters is empty an unsigned underflow occurs, causing this error message. ------------------------------------------------------------------------ [2016-09-29 20:46:07] mberchtold at gmail dot com Description: ------------ Problem ======= mail throws this fatal error if an additional_parameters (even if it is an empty string) is passed to the function: PHP Fatal error: mail(): Escaped command exceeds the allowed length of 8192 bytes Cause ===== In the mail function, the extra_cmd is escaped with php_escape_shell_cmd: https://github.com/php/php-src/blob/master/ext/standard/mail.c#L374 This is incorrect if the string is not passed to an executable. This is the case on Windows when SMTP is used (php.ini: mail.SMTP). Solution ======== The additional_parameters argument should be ignored (and therefore not be escaped) if it is not used (not passed to a shell command). Also there seems to be another bug where php_escape_shell_cmd fails if an empty string is passed. Test script: --------------- mail("test@test.com", "subject", "message", "From: lala@test.com", ""); Actual result: -------------- PHP Fatal error: mail(): Escaped command exceeds the allowed length of 8192 bytes ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73203&edit=1

« previous php.bugs (#204360) next »