Bug #78617 [NEW]: mb_decode_mimeheader does not follow RFC2047 correctly
| From: | marcus at synchromedia dot co dot uk | Date: | Tue, 01 Oct 2019 09:17:41 +0000 |
| Subject: | Bug #78617 [NEW]: mb_decode_mimeheader does not follow RFC2047 correctly | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-222972@lists.php.net to get a copy of this message | ||
From: marcus at synchromedia dot co dot uk
Operating system: any
PHP version: 7.3.10
Package: Strings related
Bug Type: Bug
Bug description:mb_decode_mimeheader does not follow RFC2047 correctly
Description:
------------
[RFC2047 section 4.2](https://tools.ietf.org/html/rfc2047#section-4.2)
describes a way of encoding 8-bit characters sets in email headers, and
in PHP that's handled by the mbstring extension. In that section, spaces
can be encoded using either
=20 or _, the latter being preferable as
it is more readable and uses fewer characters. A header encoded this way
might look like this:
X-My-Header: =?us-ascii?Q?hello_world?=
(this is a simplistic example - that header value does not actually
*need* RFC2047 encoding, though it is harmless)
The mb_decode_mimeheader function does not decode this correctly,
leaving the underscore undecoded. It does decode the alternative =20
syntax correctly.
A workaround is to encode the _ as =20 prior to decoding, as in:
mb_decode_mimeheader(str_replace('_', '=20', 'X-My-Header:
=?us-ascii?Q?hello_world?='))
Note that this should not be applied blindly because the header may not
be Q-encoded in the first place.
Test script:
---------------
echo mb_decode_mimeheader('X-My-Header: =?us-ascii?Q?hello_world?=');
Expected result:
----------------
X-My-Header: hello world
Actual result:
--------------
X-My-Header: hello_world
--
Edit bug report at https://bugs.php.net/bug.php?id=78617&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78617&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78617&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78617&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78617&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78617&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78617&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78617&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78617&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78617&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78617&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78617&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78617&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78617&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78617&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78617&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78617&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78617&r=mysqlcfg