Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers

From: Date: Tue, 14 Aug 2018 05:25:15 +0000
Subject: Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216773@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1 ID: 68776 Comment by: calltrichymap at gmail dot com Reported by: yohgaki@php.net Summary: mail() does not have mail header injection prevention for additional headers Status: Closed Type: Bug Package: Mail related Operating System: any PHP Version: Irrelevant Assigned To: yohgaki Block user comment: N Private report: N New Comment: hai , this is test message Previous Comments: ------------------------------------------------------------------------ [2018-03-13 16:47:04] cmb@php.net Related To: Bug #44187 ------------------------------------------------------------------------ [2015-09-02 13:18:50] merijn at web2all dot nl @yohgaki regarding your last comment @chaos; The documentation states 'String to be inserted at the end of the email header' and it could (and has) been used to send a MIME message. So this injection prevention fix breaks code which worked for over 10 years. And its also in a pretty important part, the sending of mail. I think this should not be fixed in minor release without any mention of a serious backwards compatibility break.... ------------------------------------------------------------------------ [2015-06-25 04:24:56] yohgaki@php.net @chaos To send multipart MIME message, users should use header and body correctly. RFC 2822 defines CRLF+CRLF as start of body. So if users are misusing $additional_headers, they have to fix their code. ------------------------------------------------------------------------ [2015-06-25 04:21:52] yohgaki@php.net @chaos We are planning to eliminate injection by this https://bugs.php.net/bug.php?id=69791 ------------------------------------------------------------------------ [2015-06-24 15:10:53] chaos at isocity dot de Thx for response. A short feedback here: <?php //Example mail with HMTL body on additional_header $uid = md5(rand()); $to = "example@example.com"; $subject = "My subject"; $headers = "From: webmaster@example.com" . "\r\n" . "MIME-Version: 1.0" . "\r\n" . "Content-Type: multipart/mixed; boundary=\"".$uid."\"" . "\r\n" . "This is a multi-part message in MIME format." . "\r\n" . "--".$uid . "\r\n" . "Content-Type: TEXT/html; CHARSET=iso-8859-1" . "\r\n" . "Content-Transfer-Encoding: BASE64" . "\r\n" . "Content-Description: htmlpart" . "\r\n" . "" . "\r\n" . "=?UTF-8?B?PHN0cm9uZz50ZXN0PC9zdHJvbmc+?=" . "\r\n" . "--".$uid; mail($to,$subject,'',$headers); ?> Warning: mail(): Multiple or malformed newlines found in additional_header in / It seems like it doesn't matter how to perform $additional_headers if something like attachments or html-body-parts are set up. Addition: If this line: "". "\r\n" . is been removed, the mail()-error doesn't apply. But unfortunately either no email is sent this way on one hosting plattform or the email is sent without body on the other. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=68776 -- Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1

« previous php.bugs (#216773) next »