Bug #2607: PHP Crash caused by mail() function
| From: | e dot wachenfeld at ndh dot net | Date: | Tue, 26 Oct 1999 17:06:55 +0000 |
| Subject: | Bug #2607: PHP Crash caused by mail() function | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-11917@lists.php.net to get a copy of this message | ||
From: e.wachenfeld@ndh.net
Operating system: Windows NT 4.0 SP 5
PHP version: 3.0.11
PHP Bug Type: Reproduceable crash
Bug description: PHP Crash caused by mail() function
The mail() function causes PHP to crash if the parameter <headers> (4th parameter of mail(),
this parameter is optional) is larger than about 3000 bytes. The cause of this crash is in the win32
module of the mail function. The <header> string is simply sprintf-ed to the output buffer
(which is 4k) without length checking. This bug could be easily fixed by sending this parameter in
smaller blocks within a loop. Will this be fixed ?