Bug #80203 [Asn->Opn]: imap_mime_header_decode() is not binary safe
| From: | cmb@php.net | Date: | Mon, 19 Oct 2020 15:52:46 +0000 |
| Subject: | Bug #80203 [Asn->Opn]: imap_mime_header_decode() is not binary safe | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-229763@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80203&edit=1
ID: 80203
Updated by: cmb@php.net
Reported by: cmb@php.net
Summary: imap_mime_header_decode() is not binary safe
-Status: Assigned
+Status: Open
Type: Bug
Package: IMAP related
Operating System: *
PHP Version: 7.3Git-2020-10-08 (Git)
-Assigned To: cmb
+Assigned To:
Block user comment: N
Private report: N
New Comment:
It appears there are several more places where the IMAP extension
is not binary safe. Fixing this piecemeal doesn't look right, but
I won't have time for a full review now.
Previous Comments:
------------------------------------------------------------------------
[2020-10-19 08:09:19] cmb@php.net
Related To: Bug #80201
------------------------------------------------------------------------
[2020-10-08 12:19:35] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #80203: imap_mime_header_decode() is not binary safe
On GitHub: https://github.com/php/php-src/pull/6301
Patch: https://github.com/php/php-src/pull/6301.patch
------------------------------------------------------------------------
[2020-10-08 12:00:27] cmb@php.net
Description:
------------
If NUL bytes are encoded in the encoded-word, the decoded text
is truncated at that position.
Test script:
---------------
<?php
var_dump(bin2hex(imap_mime_header_decode("=?UTF-8?Q?foo=00bar?=")[0]->text));
var_dump(bin2hex(imap_mime_header_decode("=?UTF-8?B?Zm9vAGJhcg==?=")[0]->text));
?>
Expected result:
----------------
string(14) "666f6f00626172"
string(14) "666f6f00626172"
Actual result:
--------------
string(6) "666f6f"
string(6) "666f6f"
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80203&edit=1