Bug #78617 [NEW]: mb_decode_mimeheader does not follow RFC2047 correctly

From: Date: Tue, 01 Oct 2019 09:17:41 +0000
Subject: Bug #78617 [NEW]: mb_decode_mimeheader does not follow RFC2047 correctly
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222972@lists.php.net to get a copy of this message
From: marcus at synchromedia dot co dot uk Operating system: any PHP version: 7.3.10 Package: Strings related Bug Type: Bug Bug description:mb_decode_mimeheader does not follow RFC2047 correctly Description: ------------ [RFC2047 section 4.2](https://tools.ietf.org/html/rfc2047#section-4.2) describes a way of encoding 8-bit characters sets in email headers, and in PHP that's handled by the mbstring extension. In that section, spaces can be encoded using either =20 or _, the latter being preferable as it is more readable and uses fewer characters. A header encoded this way might look like this: X-My-Header: =?us-ascii?Q?hello_world?= (this is a simplistic example - that header value does not actually *need* RFC2047 encoding, though it is harmless) The mb_decode_mimeheader function does not decode this correctly, leaving the underscore undecoded. It does decode the alternative =20 syntax correctly. A workaround is to encode the _ as =20 prior to decoding, as in: mb_decode_mimeheader(str_replace('_', '=20', 'X-My-Header: =?us-ascii?Q?hello_world?=')) Note that this should not be applied blindly because the header may not be Q-encoded in the first place. Test script: --------------- echo mb_decode_mimeheader('X-My-Header: =?us-ascii?Q?hello_world?='); Expected result: ---------------- X-My-Header: hello world Actual result: -------------- X-My-Header: hello_world -- Edit bug report at https://bugs.php.net/bug.php?id=78617&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=78617&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=78617&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=78617&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=78617&r=needscript Try newer version: https://bugs.php.net/fix.php?id=78617&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=78617&r=support Expected behavior: https://bugs.php.net/fix.php?id=78617&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=78617&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=78617&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=78617&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=78617&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=78617&r=dst IIS Stability: https://bugs.php.net/fix.php?id=78617&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=78617&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=78617&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=78617&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=78617&r=mysqlcfg

« previous php.bugs (#222972) next »