mirror of
https://github.com/inverse-inc/sogo.git
synced 2026-10-08 05:17:15 +00:00
fix(mail): sanitize the domain part of generated message-ids
generateMessageID: appended the substring following the last '@' without sanitizing it, so a sender value such as 'Doe, John <a@b>' produced 'Message-Id: <uuid@b>>' with a duplicated closing bracket on calendar invitations. A nil domain also left the message-id unterminated. The domain part is now cut at the first address delimiter or whitespace - a domain is a single token, and anything else would allow header injection through generated message-ids. Fixes #6201
This commit is contained in:
1 parent
5e627db80d
commit
20779cf353
3 files changed
+57
-4
No files matched your search
@@ -564,7 +564,7 @@
|
||||
{
|
||||
NSMutableString *messageID;
|
||||
NSString *_domain;
|
||||
NSRange r;
|
||||
NSRange r, cutRange;
|
||||
|
||||
messageID = [NSMutableString string];
|
||||
[messageID appendFormat: @"<%@", [SOGoObject mailUniqueMessageId]];
|
||||
@@ -578,9 +578,15 @@
|
||||
}
|
||||
else
|
||||
_domain = mailOrDomain;
|
||||
[messageID appendFormat: @"@%@>", _domain];
|
||||
_domain = [[_domain componentsSeparatedByString: @">"] objectAtIndex: 0];
|
||||
cutRange = [_domain rangeOfCharacterFromSet:
|
||||
[NSCharacterSet whitespaceAndNewlineCharacterSet]];
|
||||
if (cutRange.location != NSNotFound)
|
||||
_domain = [_domain substringToIndex: cutRange.location];
|
||||
if ([_domain length] > 0)
|
||||
[messageID appendFormat: @"@%@", _domain];
|
||||
}
|
||||
|
||||
[messageID appendString: @">"];
|
||||
|
||||
return [messageID lowercaseString];
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user