Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers
| From: | calltrichymap at gmail dot com | Date: | Tue, 14 Aug 2018 05:25:15 +0000 |
| Subject: | Bug #68776 [Com]: mail() does not have mail header injection prevention for additional headers | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-216773@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68776&edit=1
ID: 68776
Comment by: calltrichymap at gmail dot com
Reported by: yohgaki@php.net
Summary: mail() does not have mail header injection
prevention for additional headers
Status: Closed
Type: Bug
Package: Mail related
Operating System: any
PHP Version: Irrelevant
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
hai , this is test message
Previous Comments:
------------------------------------------------------------------------
[2018-03-13 16:47:04] cmb@php.net
Related To: Bug #44187
------------------------------------------------------------------------
[2015-09-02 13:18:50] merijn at web2all dot nl
@yohgaki
regarding your last comment @chaos;
The documentation states 'String to be inserted at the end of the email header' and it
could (and has) been used to send a MIME message.
So this injection prevention fix breaks code which worked for over 10 years. And its also in a
pretty important part, the sending of mail.
I think this should not be fixed in minor release without any mention of a serious backwards
compatibility break....
------------------------------------------------------------------------
[2015-06-25 04:24:56] yohgaki@php.net
@chaos
To send multipart MIME message, users should use header and body correctly. RFC 2822 defines
CRLF+CRLF as start of body. So if users are misusing $additional_headers, they have to fix their
code.
------------------------------------------------------------------------
[2015-06-25 04:21:52] yohgaki@php.net
@chaos
We are planning to eliminate injection by this
https://bugs.php.net/bug.php?id=69791
------------------------------------------------------------------------
[2015-06-24 15:10:53] chaos at isocity dot de
Thx for response.
A short feedback here:
<?php
//Example mail with HMTL body on additional_header
$uid = md5(rand());
$to = "example@example.com";
$subject = "My subject";
$headers =
"From: webmaster@example.com" . "\r\n" .
"MIME-Version: 1.0" . "\r\n" .
"Content-Type: multipart/mixed; boundary=\"".$uid."\"" .
"\r\n" .
"This is a multi-part message in MIME format." . "\r\n" .
"--".$uid . "\r\n" .
"Content-Type: TEXT/html; CHARSET=iso-8859-1" . "\r\n" .
"Content-Transfer-Encoding: BASE64" . "\r\n" .
"Content-Description: htmlpart" . "\r\n" .
"" . "\r\n" .
"=?UTF-8?B?PHN0cm9uZz50ZXN0PC9zdHJvbmc+?=" . "\r\n" .
"--".$uid;
mail($to,$subject,'',$headers);
?>
Warning: mail(): Multiple or malformed newlines found in additional_header in /
It seems like it doesn't matter how to perform $additional_headers if something like
attachments or html-body-parts are set up.
Addition: If this line: "". "\r\n" . is been removed, the mail()-error
doesn't apply. But unfortunately either no email is sent this way on one hosting plattform or
the email is sent without body on the other.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68776
--
Edit this bug report at https://bugs.php.net/bug.php?id=68776&edit=1