Bug #80216 [PATCH]: imap_mail_compose() does not validate types/encodings
| From: | cmb@php.net | Date: | Mon, 12 Oct 2020 12:10:29 +0000 |
| Subject: | Bug #80216 [PATCH]: imap_mail_compose() does not validate types/encodings | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229569@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80216&edit=1
ID: 80216
Patch added by: cmb@php.net
Reported by: cmb@php.net
Summary: imap_mail_compose() does not validate
types/encodings
Status: Assigned
Type: Bug
Package: IMAP related
Operating System: *
PHP Version: 7.3Git-2020-10-10 (Git)
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix #80216: imap_mail_compose() does not validate types/encodings
On GitHub: https://github.com/php/php-src/pull/6323
Patch: https://github.com/php/php-src/pull/6323.patch
Previous Comments:
------------------------------------------------------------------------
[2020-10-12 09:13:44] cmb@php.net
Actually, it is not just about omitting the type; more generally,
if a type < 0 or >= TYPEMAX is passed, we do OOB reads. And there
are potential issues where TYPEOTHER < type < TYPEMAX, because
these types *may* not have associated type names, in which case we
segfault as well.
The encoding parameter has basically the same issue.
------------------------------------------------------------------------
[2020-10-10 16:35:00] cmb@php.net
Description:
------------
If imap_mail_compose() is used to create a multipart MIME message
without specifying explicit types for the individual parts, that
leads to a segfault. Since the type for the first body defaults
to TYPETEXT, I would expect the individual parts to default to
TYPETEXT as well.
Test script:
---------------
<?php
$envelope = [
'from' => 'me@example.com',
'to' => 'you@example.com',
'subject' => 'hello',
];
$body = [[
'type' => TYPEMULTIPART,
], [
'contents.data' => 'yada yada',
]];
echo imap_mail_compose($envelope, $body);
?>
Expected result:
----------------
From: me@example.com
Subject: hello
To: you@example.com
MIME-Version: 1.0
Content-Type: MULTIPART/MIXED; BOUNDARY="321-1709-1602347443=:9960"
--321-1709-1602347443=:9960
Content-Type: TEXT/PLAIN; CHARSET=US-ASCII
yada yada
--321-1709-1602347443=:9960--
Actual result:
--------------
segfault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80216&edit=1