Bug #78617 [Ver]: mb_decode_mimeheader does not follow RFC2047 correctly

From: Date: Wed, 02 Oct 2019 16:52:00 +0000
Subject: Bug #78617 [Ver]: mb_decode_mimeheader does not follow RFC2047 correctly
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222996@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78617&edit=1 ID: 78617 Updated by: cmb@php.net Reported by: marcus at synchromedia dot co dot uk Summary: mb_decode_mimeheader does not follow RFC2047 correctly Status: Verified Type: Bug Package: mbstring related Operating System: any PHP Version: 7.3.10 Block user comment: N Private report: N New Comment: The actual problem here is that MBString does not distinguish between Quoted-Printable and Q encoding. Previous Comments: ------------------------------------------------------------------------ [2019-10-01 09:33:53] cmb@php.net Confirmed: <https://3v4l.org/6TlQs>. ------------------------------------------------------------------------ [2019-10-01 09:17:41] marcus at synchromedia dot co dot uk Description: ------------ [RFC2047 section 4.2](https://tools.ietf.org/html/rfc2047#section-4.2) describes a way of encoding 8-bit characters sets in email headers, and in PHP that's handled by the mbstring extension. In that section, spaces can be encoded using either =20 or _, the latter being preferable as it is more readable and uses fewer characters. A header encoded this way might look like this: X-My-Header: =?us-ascii?Q?hello_world?= (this is a simplistic example - that header value does not actually *need* RFC2047 encoding, though it is harmless) The mb_decode_mimeheader function does not decode this correctly, leaving the underscore undecoded. It does decode the alternative =20 syntax correctly. A workaround is to encode the _ as =20 prior to decoding, as in: mb_decode_mimeheader(str_replace('_', '=20', 'X-My-Header: =?us-ascii?Q?hello_world?=')) Note that this should not be applied blindly because the header may not be Q-encoded in the first place. Test script: --------------- echo mb_decode_mimeheader('X-My-Header: =?us-ascii?Q?hello_world?='); Expected result: ---------------- X-My-Header: hello world Actual result: -------------- X-My-Header: hello_world ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78617&edit=1

« previous php.bugs (#222996) next »