Bug #14983 Updated: mail function buffer overflow
| From: | sander@php.net | Date: | Sun, 03 Feb 2002 20:06:37 +0000 |
| Subject: | Bug #14983 Updated: mail function buffer overflow | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-78979@lists.php.net to get a copy of this message | ||
ID: 14983
Updated by: sander@php.net
Reported By: enricod@videotron.ca
Status: Open
Bug Type: Reproducible crash
Operating System: Windows 2000
PHP Version: 4.1.1
New Comment:
There was no feedback needed; somehow the status was still set to
feedback, therefore I closed the bug by mistake.
Sorry for the confusion :)
Previous Comments:
------------------------------------------------------------------------
[2002-02-03 14:41:50] enricod@videotron.ca
what feedback is needed ?
------------------------------------------------------------------------
[2002-02-02 06:37:30] sander@php.net
Sorry, reopening.
------------------------------------------------------------------------
[2002-02-02 06:35:57] sander@php.net
No feedback was provided for this bug, so it is being suspended.
If you are able to provide the information that was requested,
please do so and change the status of the bug back to "Open".
------------------------------------------------------------------------
[2002-01-11 11:31:01] enricod@videotron.ca
Here is the diff.
-Enrico
--- sendmail-old.c Mon Sep 4 18:26:16 2000
+++ sendmail.c Thu Jan 10 20:20:56 2002
@@ -16,6 +16,8 @@
* The complete wSendmail package with source code can be located
* from http://www.jgaa.com
*
+
+ modified by Enrico Demarin Jan 2001
*/
#include "php.h" /*php specific */
@@ -217,7 +219,7 @@
if (strchr(mailTo, '@') == NULL)
return (BAD_MSG_DESTINATION);
- sprintf(Buffer, "HELO %s\r\n", LocalHost);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "HELO %s\r\n", LocalHost);
/* in the beggining of the dialog */
/* attempt reconnect if the first Post fail */
@@ -229,7 +231,7 @@
if ((res = Ack()) != SUCCESS)
return (res);
- sprintf(Buffer, "MAIL FROM:<%s>\r\n", RPath);
+ snprintf(Buffer, MAIL_BUFFER_SIZE,"MAIL FROM:<%s>\r\n", RPath);
if ((res = Post(Buffer)) != SUCCESS)
return (res);
if ((res = Ack()) != SUCCESS)
@@ -242,7 +244,7 @@
token = strtok(tempMailTo, ",");
while(token != NULL)
{
- sprintf(Buffer, "RCPT TO:<%s>\r\n", token);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "RCPT TO:<%s>\r\n", token);
if ((res = Post(Buffer)) != SUCCESS)
return (res);
if ((res = Ack()) != SUCCESS)
@@ -259,7 +261,7 @@
token = strtok(tempMailTo, ",");
while(token != NULL)
{
- sprintf(Buffer, "RCPT TO:<%s>\r\n", token);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "RCPT TO:<%s>\r\n", token);
if ((res = Post(Buffer)) != SUCCESS)
return (res);
if ((res = Ack()) != SUCCESS)
@@ -341,14 +343,15 @@
struct tm *tm = localtime(&tNow);
int zoneh = abs(_timezone);
int zonem, res;
+ int i;
+
char *p;
- p = Buffer;
zoneh /= (60 * 60);
zonem = (abs(_timezone) / 60) - (zoneh * 60);
if(!xheaders || !strstr(xheaders, "Date:")){
- p += sprintf(p, "Date: %s, %02d %s %04d %02d:%02d:%02d
%s%02d%02d\r\n",
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "Date: %s, %02d %s %04d
%02d:%02d:%02d %s%02d%02d\r\n",
days[tm->tm_wday],
tm->tm_mday,
months[tm->tm_mon],
@@ -359,21 +362,56 @@
(_timezone > 0) ? "+" : (_timezone < 0) ? "-" : "",
zoneh,
zonem);
+
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
}
if(!xheaders || !strstr(xheaders, "From:")){
- p += sprintf(p, "From: %s\r\n", RPath);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "From: %s\r\n", RPath);
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
}
- p += sprintf(p, "Subject: %s\r\n", Subject);
+
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "Subject: %s\r\n", Subject);
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
+
if(!xheaders || !strstr(xheaders, "To:")){
- p += sprintf(p, "To: %s\r\n", mailTo);
+ snprintf(Buffer, MAIL_BUFFER_SIZE, "To: %s\r\n", mailTo);
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
}
+
if(xheaders){
- p += sprintf(p, "%s\r\n", xheaders);
- }
- if ((res = Post(Buffer)) != SUCCESS)
- return (res);
+ /* send extre headers in 1024 chunks */
+ if (strlen(xheaders) <= 1024) {
+ if ((res = Post(xheaders)) != SUCCESS)
+ return (res);
+ } else {
+ p = xheaders;
+
+ while (1) {
+ if (*p == '\0')
+ break;
+ if (strlen(p) >= 1024)
+ i = 1024;
+ else
+ i = strlen(p);
+
+ /* put next chunk in buffer */
+ strncpy(Buffer, p, i);
+ Buffer[i] = '\0';
+ p += i;
+
+ /* send chunk */
+ if ((res = Post(Buffer)) != SUCCESS)
+ return (res);
+ }
+ }
+ }
+
if ((res = Post("\r\n")) != SUCCESS)
return (res);
------------------------------------------------------------------------
[2002-01-11 11:00:08] sander@php.net
It would be nice if you post a diff instead of the whole file...
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/14983
Edit this bug report at http://bugs.php.net/?id=14983&edit=1