Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[3.10] gh-80222: Fix email address header folding with long quoted-string (GH-122753)#129111

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
ambv merged 3 commits intopython:3.10frombitdancer:backport-5aaf416-3.10
Apr 3, 2025

Conversation

bitdancer
Copy link
Member

@bitdancerbitdancer commentedJan 21, 2025
edited by bedevere-appbot
Loading

Email generators using email.policy.default could incorrectly omit the
quote ('"') characters from a quoted-string during header refolding,
leading to invalid address headers and enabling header spoofing. This
change restores the quote characters on a bare-quoted-string as the
header is refolded, and escapes backslash and quote chars in the string.
(cherry picked from commit5aaf416)

Co-authored-by: Mike Edmundsmedmunds@gmail.com

@hugovk
Copy link
Member

@bitdancer The CI is failing fortest_email, please could you check it?

@terryjreedy
Copy link
Member

bitdancer is no longer active. @python/email-team Security backport is pending fix of failing test.

@medmunds
Copy link
Contributor

The failing test_address_list_with_list_separator_after_fold was added in 3.11 by PRs#100885 and#119099 as a fix forgh-100884 (and regressiongh-118643). The test case is being pulled into 3.10 by this backport, but without the corresponding fix.

gh-100884 has similar security implications to the original issue here, but was not identified as a security issue at the time. (It's also effectively the inverse issue ofgh-121284.)

@bitdancer
Copy link
MemberAuthor

@terryjreedy Actually I'm becoming active again, but I'm still ramping back up. I'm still learning about the current way backports are done, and it has taken me a while to get back to this.

medmundsand others added2 commitsMarch 14, 2025 12:53
…ted-string (pythonGH-122753)Email generators using email.policy.default could incorrectly omit thequote ('"') characters from a quoted-string during header refolding,leading to invalid address headers and enabling header spoofing. Thischange restores the quote characters on a bare-quoted-string as theheader is refolded, and escapes backslash and quote chars in the string.(cherry picked from commit5aaf416)Co-authored-by: Mike Edmunds <medmunds@gmail.com>
@bitdancer
Copy link
MemberAuthor

Tests are passing now.

hugovk reacted with thumbs up emoji

@ambvambv merged commita4ef689 intopython:3.10Apr 3, 2025
15 checks passed
@bedevere-app
Copy link

GH-132371 is a backport of this pull request to the3.9 branch.

@terryjreedy
Copy link
Member

@bitdancer Good to see you back ;-). Are you aware of core-dev discord?

@bitdancer
Copy link
MemberAuthor

@terryjreedy Aware, yes, but I haven't gotten around to trying to figure out how to access it ;)

@terryjreedy
Copy link
Member

Once you have an account, I believe you need an invite from an admin.@hugovk@ambv ?

@hugovk
Copy link
Member

@bitdancer I've sent an invite to the email on your profile. Welcome!

ambv added a commit that referenced this pull requestJun 2, 2025
…ing (GH-122753) (GH-129111) (GH-132371)Email generators using email.policy.default could incorrectly omit thequote ('"') characters from a quoted-string during header refolding,leading to invalid address headers and enabling header spoofing. Thischange restores the quote characters on a bare-quoted-string as theheader is refolded, and escapes backslash and quote chars in the string.(cherry picked from commit5aaf416)(cherry picked from commita4ef689)Co-authored-by: R. David Murray <rdmurray@bitdance.com>Co-authored-by: Mike Edmunds <medmunds@gmail.com>Co-authored-by: Łukasz Langa <lukasz@langa.pl>
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment
Reviewers

@pablogsalpablogsalAwaiting requested review from pablogsal

Assignees

@bitdancerbitdancer

Projects
Milestone
No milestone
Development

Successfully merging this pull request may close these issues.

6 participants
@bitdancer@hugovk@terryjreedy@medmunds@ambv@sethmlarson

[8]ページ先頭

©2009-2025 Movatter.jp