Bug #78617 [Ver]: mb_decode_mimeheader does not follow RFC2047 correctly
| From: | cmb@php.net | Date: | Wed, 02 Oct 2019 16:52:00 +0000 |
| Subject: | Bug #78617 [Ver]: mb_decode_mimeheader does not follow RFC2047 correctly | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222996@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78617&edit=1
ID: 78617
Updated by: cmb@php.net
Reported by: marcus at synchromedia dot co dot uk
Summary: mb_decode_mimeheader does not follow RFC2047
correctly
Status: Verified
Type: Bug
Package: mbstring related
Operating System: any
PHP Version: 7.3.10
Block user comment: N
Private report: N
New Comment:
The actual problem here is that MBString does not distinguish
between Quoted-Printable and Q encoding.
Previous Comments:
------------------------------------------------------------------------
[2019-10-01 09:33:53] cmb@php.net
Confirmed: <https://3v4l.org/6TlQs>.
------------------------------------------------------------------------
[2019-10-01 09:17:41] marcus at synchromedia dot co dot uk
Description:
------------
[RFC2047 section 4.2](https://tools.ietf.org/html/rfc2047#section-4.2) describes a way of encoding
8-bit characters sets in email headers, and in PHP that's handled by the mbstring extension. In
that section, spaces can be encoded using either
=20 or _, the latter
being preferable as it is more readable and uses fewer characters. A header encoded this way might
look like this:
X-My-Header: =?us-ascii?Q?hello_world?=
(this is a simplistic example - that header value does not actually *need* RFC2047 encoding, though
it is harmless)
The mb_decode_mimeheader function does not decode this correctly, leaving the underscore undecoded.
It does decode the alternative =20 syntax correctly.
A workaround is to encode the _ as =20 prior to decoding, as in:
mb_decode_mimeheader(str_replace('_', '=20', 'X-My-Header:
=?us-ascii?Q?hello_world?='))
Note that this should not be applied blindly because the header may not be Q-encoded in the first
place.
Test script:
---------------
echo mb_decode_mimeheader('X-My-Header: =?us-ascii?Q?hello_world?=');
Expected result:
----------------
X-My-Header: hello world
Actual result:
--------------
X-My-Header: hello_world
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78617&edit=1