Sec Bug->Bug #74139 [Opn->Ver]: mail.add_x_header default inconsistent with docs, presents minor security risk

From: Date: Tue, 13 Mar 2018 22:46:19 +0000
Subject: Sec Bug->Bug #74139 [Opn->Ver]: mail.add_x_header default inconsistent with docs, presents minor security risk
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214346@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74139&edit=1 ID: 74139 Updated by: cmb@php.net Reported by: marcus at synchromedia dot co dot uk Summary: mail.add_x_header default inconsistent with docs, presents minor security risk -Status: Open +Status: Verified -Type: Security +Type: Bug Package: Mail related Operating System: All PHP Version: 7.1.2 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: Thanks for the report – and sorry for the late reply! While I certainly agree that the respective values in the default php.inis should be fixed (since mail.add_x_header actually defaults to 0[1]), I don't think this qualifies a security issue, since the possibly leaking information is rather humble, and users are supposed to be aware of such information leakage. [1] <https://github.com/php/php-src/blob/PHP-7.2.4/main/main.c#L613> Previous Comments: ------------------------------------------------------------------------ [2017-02-21 09:10:36] marcus at synchromedia dot co dot uk Description: ------------ On the documentation page for mail() runtime configuration, it says that the mail.add_x_header config option is 0 by default, however, it is set to On in the php.ini development and production ini files provided with PHP, and as a consequence, defaults to that value in every packaged version of PHP I've found. This is a security risk as it represents an unnecessary leak of information (disclosing both PID and script name) that may be of use to attackers. Docs: http://php.net/manual/en/mail.configuration.php#ini.mail.add-x-header Default php.ini: https://github.com/php/php-src/blob/master/php.ini-production#L1052 As well as being a minor security risk, the addition of this header is done incorrectly in PHP versions between 7.0.0 - 7.0.16 and 7.1.0 - 7.1.2 since the header addition uses an incorrect line break format (see bug https://bugs.php.net/bug.php?id=74005). This was fixed in PHP 7.1.3 and 7.0.17. This bug, when combined with the inconsistent ini setting will result in mail sending failures or corrupted messages in affected PHP versions. An appropriate fix would be to set the default in provided php.ini files to the value described in documentation, i.e. mail.add_x_header = 0. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74139&edit=1

« previous php.bugs (#214346) next »