Bug #72964 [PATCH]: White space not unfolded for CC/Bcc headers

From: Date: Tue, 10 Nov 2020 15:31:24 +0000
Subject: Bug #72964 [PATCH]: White space not unfolded for CC/Bcc headers
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230252@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72964&edit=1

 ID:                 72964
 Patch added by:     cmb@php.net
 Reported by:        hynek dot petrak at gmail dot com
 Summary:            White space not unfolded for CC/Bcc headers
 Status:             Verified
 Type:               Bug
 Package:            Mail related
 Operating System:   Windows
 PHP Version:        5.6.25
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

The following pull request has been associated:

Patch Name: Fix #72964: White space not unfolded for CC/Bcc headers
On GitHub:  https://github.com/php/php-src/pull/6420
Patch:      https://github.com/php/php-src/pull/6420.patch


Previous Comments:
------------------------------------------------------------------------
[2016-08-29 12:40:55] hynek dot petrak at gmail dot com

Description:
------------
According to RFC2822 / 2.2.3. Long Header Fields, each header field can use White space folding.
E.g.:

To: xy@example.com\r\n
CC: ab@example.com,\r\n
 cd@example.com\r\n
Subject: subject text

In the win32/sendmail.c SendText() function, the cc: and bcc: headers are considered only up to the
next \r\n, ignoring any additional folded lines. This occures on Windows when
"sendmail_path" is not defined in php.ini.

Problematic code:
                pos1 = headers + (pos1 - headers_lc) + 3;
                if (NULL == (pos2 = strstr(pos1, "\r\n"))) {
                        tempMailTo = estrndup(pos1, strlen(pos1));
                } else {
                        tempMailTo = estrndup(pos1, pos2 - pos1);
                }
IMHO any folding sequence "\r\n\t" or "\r\n " shall be replaced with
"\t" or " " in header_lc before scanning. Other solutions might be convenient
too.



Test script:
---------------
<?php
$to      = 'nobody@example.com';
$subject = 'the subject';
$message = 'hello';
$headers = 'From: webmaster@example.com' . "\r\n" .
    'Cc: cc1@example.com' . "\r\n" . ', ' .
    '\tcc2@example.com' . "\r\n" .
    'X-Mailer: PHP/' . phpversion();

mail($to, $subject, $message, $headers);
?>

Expected result:
----------------
cc2@example.com shall receive an email.

Actual result:
--------------
cc2@example.com does not receive an email. in the SMTP protocol RCPT TO: cc2@example.com is missing.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72964&edit=1


Thread (6 messages)

« previous php.bugs (#230252) next »