Sec Bug->Bug #74139 [Opn->Ver]: mail.add_x_header default inconsistent with docs, presents minor security risk
| From: | cmb@php.net | Date: | Tue, 13 Mar 2018 22:46:19 +0000 |
| Subject: | Sec Bug->Bug #74139 [Opn->Ver]: mail.add_x_header default inconsistent with docs, presents minor security risk | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214346@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74139&edit=1
ID: 74139
Updated by: cmb@php.net
Reported by: marcus at synchromedia dot co dot uk
Summary: mail.add_x_header default inconsistent with docs,
presents minor security risk
-Status: Open
+Status: Verified
-Type: Security
+Type: Bug
Package: Mail related
Operating System: All
PHP Version: 7.1.2
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Thanks for the report â and sorry for the late reply!
While I certainly agree that the respective values in the default
php.inis should be fixed (since mail.add_x_header actually
defaults to 0[1]), I don't think this qualifies a security issue,
since the possibly leaking information is rather humble, and users
are supposed to be aware of such information leakage.
[1] <https://github.com/php/php-src/blob/PHP-7.2.4/main/main.c#L613>
Previous Comments:
------------------------------------------------------------------------
[2017-02-21 09:10:36] marcus at synchromedia dot co dot uk
Description:
------------
On the documentation page for mail() runtime configuration, it says that the
mail.add_x_header config option is 0 by default, however, it is set to
On in the php.ini development and production ini files provided with PHP, and as a
consequence, defaults to that value in every packaged version of PHP I've found. This is a
security risk as it represents an unnecessary leak of information (disclosing both PID and script
name) that may be of use to attackers.
Docs:
http://php.net/manual/en/mail.configuration.php#ini.mail.add-x-header
Default php.ini:
https://github.com/php/php-src/blob/master/php.ini-production#L1052
As well as being a minor security risk, the addition of this header is done incorrectly in PHP
versions between 7.0.0 - 7.0.16 and 7.1.0 - 7.1.2 since the header addition uses an incorrect line
break format (see bug https://bugs.php.net/bug.php?id=74005). This was
fixed in PHP 7.1.3 and 7.0.17. This bug, when combined with the inconsistent ini setting will result
in mail sending failures or corrupted messages in affected PHP versions.
An appropriate fix would be to set the default in provided php.ini files to the value described in
documentation, i.e. mail.add_x_header = 0.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74139&edit=1