Bug #14983 Updated: mail function buffer overflow
| From: | mfischer@php.net | Date: | Tue, 14 May 2002 14:00:07 +0000 |
| Subject: | Bug #14983 Updated: mail function buffer overflow | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-7639@lists.php.net to get a copy of this message | ||
ID: 14983
Updated by: mfischer@php.net
Reported By: enricod@videotron.ca
-Status: Open
+Status: Feedback
Bug Type: Reproducible crash
Operating System: Windows 2000
PHP Version: 4.1.1
New Comment:
Hi enricod@videotron.ca, it took a while :) but can you send me a diff
against latest CVS HEAD ? I promise it won't linger this time.
Previous Comments:
------------------------------------------------------------------------
[2002-02-03 15:06:37] sander@php.net
There was no feedback needed; somehow the status was still set to
feedback, therefore I closed the bug by mistake.
Sorry for the confusion :)
------------------------------------------------------------------------
[2002-02-03 14:41:50] enricod@videotron.ca
what feedback is needed ?
------------------------------------------------------------------------
[2002-02-02 06:37:30] sander@php.net
Sorry, reopening.
------------------------------------------------------------------------
[2002-02-02 06:35:57] sander@php.net
No feedback was provided for this bug, so it is being suspended.
If you are able to provide the information that was requested,
please do so and change the status of the bug back to "Open".
------------------------------------------------------------------------
[2002-01-11 11:31:01] enricod@videotron.ca
Here is the diff.
-Enrico
--- sendmail-old.c Mon Sep 4 18:26:16 2000
+++ sendmail.c Thu Jan 10 20:20:56 2002
@@ -16,6 +16,8 @@
* The complete wSendmail package with source code can be located
* from http://www.jgaa.com
*
+
+ modified by Enrico Demarin Jan 2001
*/
#include "php.h" /*php specific */
@@ -217,7 +219,7 @@
if (strchr(mailTo, '@') == NULL)
return (BAD_MSG_DESTINATION);
- sprintf(Buffer, "HELO %s\r\n", LocalHost);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "HELO %s\r\n", LocalHost);
/* in the beggining of the dialog */
/* attempt reconnect if the first Post fail */
@@ -229,7 +231,7 @@
if ((res = Ack()) != SUCCESS)
return (res);
- sprintf(Buffer, "MAIL FROM:<%s>\r\n", RPath);
+ snprintf(Buffer, MAIL_BUFFER_SIZE,"MAIL FROM:<%s>\r\n", RPath);
if ((res = Post(Buffer)) != SUCCESS)
return (res);
if ((res = Ack()) != SUCCESS)
@@ -242,7 +244,7 @@
token = strtok(tempMailTo, ",");
while(token != NULL)
{
- sprintf(Buffer, "RCPT TO:<%s>\r\n", token);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "RCPT TO:<%s>\r\n", token);
if ((res = Post(Buffer)) != SUCCESS)
return (res);
if ((res = Ack()) != SUCCESS)
@@ -259,7 +261,7 @@
token = strtok(tempMailTo, ",");
while(token != NULL)
{
- sprintf(Buffer, "RCPT TO:<%s>\r\n", token);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "RCPT TO:<%s>\r\n", token);
if ((res = Post(Buffer)) != SUCCESS)
return (res);
if ((res = Ack()) != SUCCESS)
@@ -341,14 +343,15 @@
struct tm *tm = localtime(&tNow);
int zoneh = abs(_timezone);
int zonem, res;
+ int i;
+
char *p;
- p = Buffer;
zoneh /= (60 * 60);
zonem = (abs(_timezone) / 60) - (zoneh * 60);
if(!xheaders || !strstr(xheaders, "Date:")){
- p += sprintf(p, "Date: %s, %02d %s %04d %02d:%02d:%02d
%s%02d%02d\r\n",
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "Date: %s, %02d %s %04d
%02d:%02d:%02d %s%02d%02d\r\n",
days[tm->tm_wday],
tm->tm_mday,
months[tm->tm_mon],
@@ -359,21 +362,56 @@
(_timezone > 0) ? "+" : (_timezone < 0) ? "-" : "",
zoneh,
zonem);
+
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
}
if(!xheaders || !strstr(xheaders, "From:")){
- p += sprintf(p, "From: %s\r\n", RPath);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "From: %s\r\n", RPath);
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
}
- p += sprintf(p, "Subject: %s\r\n", Subject);
+
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "Subject: %s\r\n", Subject);
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
+
if(!xheaders || !strstr(xheaders, "To:")){
- p += sprintf(p, "To: %s\r\n", mailTo);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "To: %s\r\n", mailTo);
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
}
+
if(xheaders){
- p += sprintf(p, "%s\r\n", xheaders);
- }
- if ((res = Post(Buffer)) != SUCCESS)
- return (res);
+ /* send extre headers in 1024 chunks */
+ if (strlen(xheaders) <= 1024) {
+ if ((res = Post(xheaders)) != SUCCESS)
+ return (res);
+ } else {
+ p = xheaders;
+
+ while (1) {
+ if (*p == '\0')
+ break;
+ if (strlen(p) >= 1024)
+ i = 1024;
+ else
+ i = strlen(p);
+
+ /* put next chunk in buffer */
+ strncpy(Buffer, p, i);
+ Buffer[i] = '\0';
+ p += i;
+
+ /* send chunk */
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
+ }
+ }
+ }
+
if ((res = Post("\r\n")) != SUCCESS)
return (res);
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/14983
--
Edit this bug report at http://bugs.php.net/?id=14983&edit=1