#22939 [Opn->Fbk]: imap_header_info crashes a page when the from, cc or bcc field is () or <>
| From: | iliaa@php.net | Date: | Mon, 31 Mar 2003 21:16:47 +0000 |
| Subject: | #22939 [Opn->Fbk]: imap_header_info crashes a page when the from, cc or bcc field is () or <> | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-36850@lists.php.net to get a copy of this message | ||
ID: 22939
Updated by: iliaa@php.net
Reported By: simon dot wilmer at milestoneip dot com
-Status: Open
+Status: Feedback
Bug Type: IMAP related
Operating System: Red Hat 8.0
PHP Version: 4.3.1
New Comment:
Please try using this CVS snapshot:
http://snaps.php.net/php4-STABLE-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php4-win32-STABLE-latest.zip
Previous Comments:
------------------------------------------------------------------------
[2003-03-28 09:53:17] simon dot wilmer at milestoneip dot com
Hi,
Using PHP 4.3.0 and 4.3.1 with IMAP_2001.RELEASE-CANDIDATE.1 and
IMAP_2003.DEV.SNAP-0303181124 and Apache 1.3.27. The imap_header_info
function returns an obkect with headers from an email, when trying to
read the ->to, ->toaddress, ->cc, ->ccaddress, ->bcc, ->bccaddress
values the page will crash if the from, cc or bcc field in the email
itself is "()" or "<>" in the headers. Any normal text is fine, but the
values above cause the page to crash.
There is no error message returned unfortunately. Below is some sample
code to test this.
Also you will need to set the "from" in an email to () or <> to cause
the problem. If anyone thinks it's a good idea I might email
security@php.net as someone could "break" the mailbox of any web based
email system by mailing an email with a "broken" from field.
Sample code:
<?
$connection = imap_open('{localhost:143}INBOX', 'username',
'password');
$headers = imap_headerinfo($connection, 1);
echo $headers->subject." <br>";
$var = $headers->from;
if (is_array($var))
{
//This line is where the script "hangs"
echo $var[0]->mailbox."@".$var[0]->host;
}
?>
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=22939&edit=1