Bug #69791 [Asn->Csd]: Disallow mail header injections by extra headers
Edit report at https://bugs.php.net/bug.php?id=69791&edit=1
ID: 69791
Updated by: yohgaki@php.net
Reported by: yohgaki@php.net
Summary: Disallow mail header injections by extra headers
-Status: Assigned
+Status: Closed
Type: Bug
Package: Mail related
Operating System: any
PHP Version: master-Git-2015-06-10 (Git)
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Implemented in PHP 7.1.
Previous Comments:
------------------------------------------------------------------------
[2016-08-06 01:20:04] kalle@php.net
I think this is a rather elegant solution, and it can be implemented in a sort of BC compatible way
since the $extra_headers argument is expected to be a string. We could then move forward with
E_DEPRECATED for sometime in 7.x and later force it to be an array.
+1
------------------------------------------------------------------------
[2015-06-23 20:03:30] cmb@php.net
Related To: Bug #68776
------------------------------------------------------------------------
[2015-06-10 08:42:19] yohgaki@php.net
Description:
------------
Current mail() and mb_send_mail() accepts additional headers as single string. Therefore, these
functions are weak to mail header injections.
To avoid injections, mail/mb_send_mail should be able to accept additional headers as array that
contains each element as single header. RFC 2822 "3.6. Field definitions" restricts
certain header only once.
https://tools.ietf.org/html/rfc2822#section-3.6
e.g. to, from, cc, bcc, subject, etc.
Except these headers, mail/mb_send_mail should be able to set a headers multiple times.
Example additional headers array
$extra_headers = ["Bcc"=>"php@php.net",
"X-Other"=>["One", "Two"]];
Since "To" and "Subject" have dedicated parameters, $extra_headers should not
contain "To" and "Subject".
Related bugs
- https://bugs.php.net/bug.php?id=15841
- https://bugs.php.net/bug.php?id=14799
- https://bugs.php.net/bug.php?id=68776
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69791&edit=1
Thread (4 messages)