#32311 [Csd]: mb_encode_mimeheader does not properly escape characters
| From: | moriyoshi@php.net | Date: | Thu, 24 Mar 2005 00:00:42 +0000 |
| Subject: | #32311 [Csd]: mb_encode_mimeheader does not properly escape characters | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-77106@lists.php.net to get a copy of this message | ||
ID: 32311
Updated by: moriyoshi@php.net
Reported By: mortoray at ecircle-ag dot com
Status: Closed
Bug Type: mbstring related
Operating System: Irrelevant
PHP Version: *
New Comment:
The fix won't go in either 4.3.11 or 5.0.4.
Previous Comments:
------------------------------------------------------------------------
[2005-03-24 00:48:03] moriyoshi@php.net
This bug has been fixed in CVS.
Snapshots of the sources are packaged every three hours; this change
will be in the next snapshot. You can grab the snapshot at
http://snaps.php.net/.
Thank you for the report, and for helping us make PHP better.
------------------------------------------------------------------------
[2005-03-18 09:13:19] mortoray at ecircle-ag dot com
I tried the snapshot and got the same results. What appears to be
happening is that the encoders detection of disallowed characters does
not include the escape sequences required to do the encoding.
That is, as long as the string is 7-bit ASCII no encoding is ever done,
even if a MIME escape occurs in the source string, no encoding will be
done.
From the reproduction, it is obviously expected that a MIME escape
sequence will also be properly encoded.
------------------------------------------------------------------------
[2005-03-17 18:09:26] iliaa@php.net
Please try using this CVS snapshot:
http://snaps.php.net/php4-STABLE-latest.tar.gz
For Windows:
http://snaps.php.net/win32/php4-win32-STABLE-latest.zip
------------------------------------------------------------------------
[2005-03-15 10:30:51] mortoray at ecircle-ag dot com
Description:
------------
At least for Q encoding, this function is unsafe and does not encode
correctly. Raw characters which appear as RFC2047 sequences are simply
left as is.
Ex:
mb_encode_mimeheader( '=?iso-8859-1?q?this=20is=20some=20text?=' );
returns '=?iso-8859-1?q?this=20is=20some=20text?='
The exact same string, which is obviously not the encoding for the
source string. That is, mb_encode_mimeheader does not do any type of
escaping.
That is, the following condition is not always true:
mb_decode_mimeheader( mb_encode_mimeheader( $text ) ) == $text
Reproduce code:
---------------
$text = '=?iso-8859-1?q?this=20is=20some=20text?=';
assert( mb_decode_mimeheader( mb_encode_mimeheader( $text ) ) == $text
);
Expected result:
----------------
The decode/encode sequence should always return the original text.
Actual result:
--------------
Returned result is different than original (that is, the assertion
fails).
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=32311&edit=1