Bug #80216 [PATCH]: imap_mail_compose() does not validate types/encodings

From: Date: Mon, 12 Oct 2020 12:10:29 +0000
Subject: Bug #80216 [PATCH]: imap_mail_compose() does not validate types/encodings
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229569@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80216&edit=1 ID: 80216 Patch added by: cmb@php.net Reported by: cmb@php.net Summary: imap_mail_compose() does not validate types/encodings Status: Assigned Type: Bug Package: IMAP related Operating System: * PHP Version: 7.3Git-2020-10-10 (Git) Assigned To: cmb Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Fix #80216: imap_mail_compose() does not validate types/encodings On GitHub: https://github.com/php/php-src/pull/6323 Patch: https://github.com/php/php-src/pull/6323.patch Previous Comments: ------------------------------------------------------------------------ [2020-10-12 09:13:44] cmb@php.net Actually, it is not just about omitting the type; more generally, if a type < 0 or >= TYPEMAX is passed, we do OOB reads. And there are potential issues where TYPEOTHER < type < TYPEMAX, because these types *may* not have associated type names, in which case we segfault as well. The encoding parameter has basically the same issue. ------------------------------------------------------------------------ [2020-10-10 16:35:00] cmb@php.net Description: ------------ If imap_mail_compose() is used to create a multipart MIME message without specifying explicit types for the individual parts, that leads to a segfault. Since the type for the first body defaults to TYPETEXT, I would expect the individual parts to default to TYPETEXT as well. Test script: --------------- <?php $envelope = [ 'from' => 'me@example.com', 'to' => 'you@example.com', 'subject' => 'hello', ]; $body = [[ 'type' => TYPEMULTIPART, ], [ 'contents.data' => 'yada yada', ]]; echo imap_mail_compose($envelope, $body); ?> Expected result: ---------------- From: me@example.com Subject: hello To: you@example.com MIME-Version: 1.0 Content-Type: MULTIPART/MIXED; BOUNDARY="321-1709-1602347443=:9960" --321-1709-1602347443=:9960 Content-Type: TEXT/PLAIN; CHARSET=US-ASCII yada yada --321-1709-1602347443=:9960-- Actual result: -------------- segfault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80216&edit=1

« previous php.bugs (#229569) next »