Bug #80215 [PATCH]: imap_mail_compose() may modify by-val parameters

From: Date: Sat, 10 Oct 2020 15:31:14 +0000
Subject: Bug #80215 [PATCH]: imap_mail_compose() may modify by-val parameters
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229511@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80215&edit=1 ID: 80215 Patch added by: cmb@php.net Reported by: cmb@php.net Summary: imap_mail_compose() may modify by-val parameters Status: Assigned Type: Bug Package: IMAP related Operating System: * PHP Version: 7.3Git-2020-10-10 (Git) Assigned To: cmb Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Fix #80215: imap_mail_compose() may modify by-val parameters On GitHub: https://github.com/php/php-src/pull/6316 Patch: https://github.com/php/php-src/pull/6316.patch Previous Comments: ------------------------------------------------------------------------ [2020-10-10 12:39:13] cmb@php.net Description: ------------ imap_mail_compose() accepts two possibly nested arrays of strings, and due to type juggling, may actually convert the elements to string. Test script: --------------- <?php $envelope = [ "from" => 1, "to" => 2, "custom_headers" => [3], ]; $body = [[ "contents.data" => 4, "type.parameters" => ['foo' => 5], "disposition" => ['bar' => 6], ], [ "contents.data" => 7, "type.parameters" => ['foo' => 8], "disposition" => ['bar' => 9], ]]; imap_mail_compose($envelope, $body); var_dump($envelope, $body); ?> Expected result: ---------------- array(3) { ["from"]=> int(1) ["to"]=> int(2) ["custom_headers"]=> array(1) { [0]=> int(3) } } array(2) { [0]=> array(3) { ["contents.data"]=> int(4) ["type.parameters"]=> array(1) { ["foo"]=> int(5) } ["disposition"]=> array(1) { ["bar"]=> int(6) } } [1]=> array(3) { ["contents.data"]=> int(7) ["type.parameters"]=> array(1) { ["foo"]=> int(8) } ["disposition"]=> array(1) { ["bar"]=> int(9) } } } Actual result: -------------- array(3) { ["from"]=> string(1) "1" ["to"]=> string(1) "2" ["custom_headers"]=> array(1) { [0]=> string(1) "3" } } array(2) { [0]=> array(3) { ["contents.data"]=> string(1) "4" ["type.parameters"]=> array(1) { ["foo"]=> string(1) "5" } ["disposition"]=> array(1) { ["bar"]=> string(1) "6" } } [1]=> array(3) { ["contents.data"]=> string(1) "7" ["type.parameters"]=> array(1) { ["foo"]=> string(1) "8" } ["disposition"]=> array(1) { ["bar"]=> string(1) "9" } } } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80215&edit=1

« previous php.bugs (#229511) next »