Explorar el Código

fix for security exploit described in bug #812690 reported by Neal Krawetz
(hackerfactor)

stekkel hace 22 años
padre
commit
3891538bb1
Se han modificado 1 ficheros con 1 adiciones y 1 borrados
  1. 1 1
      class/deliver/Deliver_SendMail.class.php

+ 1 - 1
class/deliver/Deliver_SendMail.class.php

@@ -23,7 +23,7 @@ class Deliver_SendMail extends Deliver {
     function initStream($message, $sendmail_path) {
         $rfc822_header = $message->rfc822_header;
 	$from = $rfc822_header->from[0];
-	$envelopefrom = $from->mailbox.'@'.$from->host;
+	$envelopefrom = trim($from->mailbox.'@'.$from->host);
 	if (strstr($sendmail_path, "qmail-inject")) {
     	    $stream = popen (escapeshellcmd("$sendmail_path -i -f$envelopefrom"), "w");
 	} else {